
pyCobaltHound
Automates BloodHound integration with Cobalt Strike to discover AD escalation paths, mark compromised assets as owned, and investigate beacon…

Automates BloodHound integration with Cobalt Strike to discover AD escalation paths, mark compromised assets as owned, and investigate beacon…

Master's thesis research on CVE-2025-55182 (React2Shell). Modular exploitation framework with 6 attack scenarios (RCE, exfiltration, defacement),…

ICMP-based command and control server/client for covert remote command execution via ping packet payloads. Includes Python and PowerShell clients for…

Windows post-exploitation tool using API hooking to intercept network traffic and capture plain-text or decrypted data from low-privileged processes…

Reports on post-exploitation on honeypot exploiting vulnerable wu-ftpd (CVE-2001-0550)

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

Tools and Techniques for Red Team / Penetration Testing

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

Comprehensive red teaming notes covering offensive security techniques including code injection, defense evasion, lateral movement, and persistence,…

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Automated backdoor and payload generator that compiles cross-platform malware with AV evasion, leveraging MSFvenom and Metasploit for…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

AI-native security testing platform integrating 100+ tools with agentic orchestration, role-based testing, MCP-native tools, C2 capabilities, and…