
Penetration-Testing-Walkthrough-Hacksudo-Thor
Step-by-step black-box penetration test walkthrough exploiting Shellshock RCE (CVE-2014-6271) via Apache mod_cgi, chained with sudo misconfiguration…

Step-by-step black-box penetration test walkthrough exploiting Shellshock RCE (CVE-2014-6271) via Apache mod_cgi, chained with sudo misconfiguration…

SSH-based post-exploitation framework deploying persistent backdoors (bash, Python, Metasploit) with modules for cron, startup, and privilege…

Executes position independent shellcode from an encrypted zip

Realistic APT adversary simulation campaigns with custom C2 frameworks, backdoors, stagers, and bootloaders mirroring state-sponsored TTPs for red…

Framework for rapid prototyping of custom command-and-control channels with integration into Cobalt Strike and support for esoteric C2 transports via…

Cobalt Strike BOF for in-process .NET assembly execution with AMSI/ETW bypass, custom AppDomain, and named pipe/mailslot output redirection.

Extracts and decrypts browser-stored credentials, cookies, tokens, and history from Chromium and Gecko browsers using DLL injection, APC injection,…

PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

Cobalt Strike Beacon Object File for automated, targeted user surveillance. Triggers screenshots or custom actions when specific window titles (e.g.,…

Custom firmware framework for PS Vita that patches the kernel, disables code-signing checks, and provides a hooking API for developing kernel and…

PowerShell script for local privilege escalation via PrintNightmare (CVE-2021-34527). Injects a custom DLL payload to add a local admin user,…

Dumping LSASS with a duplicated handle from custom LSA plugin

Windows DLL proxying tool for local and remote DLL hijacking via SMB and DCOM. Generates proxy DLL payloads with custom commands, supporting Kerberos…

Proof-of-concept implementation of Cobalt Strike's external C2 feature, enabling custom communication channels for beacon callbacks. Includes C and…

Pascal-based macOS RAT with TCP command-and-control, custom payload bundling, and remote access capabilities for penetration testing and red team…

Dumps LSASS memory by abusing Microsoft-signed WindowsApp createdump.exe, using a custom dbgcore.dll hook and winlogon impersonation for credential…

Framework for building custom command-and-control protocols and integrating them with the Covenant C2 platform, enabling rapid development of…

Automated credential dumping tool with custom PowerShell payloads, in-memory execution, Mimikatz parsing, ticket dumping, and web-based dashboard for…