
PowerLurk
Malicious WMI Events using PowerShell

Malicious WMI Events using PowerShell

Weaponizes Selenium to automate credential theft, cookie dumping, email exfiltration, and file extraction from Chromium browsers for red team…

Sinister is Windows/Linux Keylogger Generator which sends key-logs via email with other juicy target info

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

scavenger : is a multi-threaded post-exploitation scanning tool for scavenging systems, finding most frequently used files and folders as well as…

swap_digger is a tool used to automate Linux swap analysis during post-exploitation or forensics. It automates swap extraction and searches for Linux…

.NET 2.0 CLR project to retrieve saved browser credentials from Google Chrome, Mozilla Firefox and Microsoft Internet Explorer/Edge.

Extract stored credentials from Internet Explorer and Edge

A macOS enumeration tool inspired by harmjoy's Windows-based Seatbelt enumeration tool. Author: Cedric Owens

A lightweight, portable, and modular tool for Linux enumeration and privilege escalation.

A python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those…

C# tool to retrieve LAPS passwords from Active Directory via LDAP, designed for in-memory execution within Cobalt Strike sessions using…

A command shell wrapper using only WMI for Microsoft Windows

Assist reverse tcp shells in post-exploration tasks

CredsHunter - Credential Hunting scripts for Windows and Linux OS

Bash script purposed for system enumeration, vulnerability identification and privilege escalation.

Abusing Azure services over C2

C# tool to dump all cookies from Chrome/Edge browsers, including httpOnly and secure flags, for session hijacking and post-exploitation credential…