

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

A python tool to map the access rights of network shares into a BloodHound OpenGraphs easily

Web application penetration testing project targeting a WordPress environment. Includes exploitation of CVE-2019-9978, reverse shell execution,…

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

Walkthroughs for Capture the Flag challenges on the HTB Cybersecurity Platform.

This tool demonstrates the application of fundamental physics discoveries to cybersecurity.

The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The…

ACEshark is a utility designed for rapid extraction and analysis of Windows service configurations and Access Control Entries, eliminating the need…

PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Android Remote Administration Tool

A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies

A PoC application demonstrating the power of an Android kernel arbitrary R/W.

A VBA implementation of the RunPE technique or how to bypass application whitelisting.

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

A PoC Java Stager which can download, compile, and execute a Java file in memory.