
createdump
Leverage WindowsApp createdump tool to obtain an lsass dump

Leverage WindowsApp createdump tool to obtain an lsass dump

Ping Exfiltration Command and Control (PiX-C2)

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then reflective load…

A fully featured Windows backdoor that uses Gmail as a C&C server

A PoC backdoor that uses Gmail as a C&C server

A User Impersonation tool - via Token or Shellcode injection

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

A fully featured backdoor that uses Twitter as a C&C server

.NET tool for installing Windows persistence via registry keys, scheduled tasks, services, WMI events, COM hijacks, and LNK backdoors, supporting…

We developed GRAT2 Command & Control (C2) project for learning purpose.

RedSails is a Python based post-exploitation project aimed at bypassing host based security monitoring and logging. DerbyCon 2017 Talk:…

A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or process handles.

A version of CVE-2017-0213 that I plan to use with an Empire stager

.NET Project for performing Authenticated Remote Execution

Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

Pass the Hash to a named pipe for token Impersonation