
SynthAPT
Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…


This is a PowerShell based tool that is designed to act like a RAT. Its interface is that of a shell where any command that is supported is…

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.

I'll submit the poc after blackhat


EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

A tool to transform Chromium browsers into a C2 Implant

This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables…

Responsive Command and Control System

Inject DLLs into the explorer process using icons

The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.

USB Army Knife – the ultimate close access tool for penetration testers and red teamers.

Post exploitation technique to turn arbitrary kernel write / increment into full read/write primitive on Windows 11 22H2

WNF Code Execution Library Using C#

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

Pupy is an opensource, multi-platform (Windows, Linux, OSX, Android), multi function RAT (Remote Administration Tool) mainly written in python. It…