
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

proxychains - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or…

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.

Six Degrees of Domain Admin

Starkiller is a Frontend for PowerShell Empire.

Burp Plugin to Bypass WAFs through the insertion of Junk Data

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

A security scanner for your LLM agentic workflows

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

A VBA implementation of the RunPE technique or how to bypass application whitelisting.

TCP tunneling over HTTP/HTTPS for web application servers

.NET/PowerShell/VBA Offensive Security Obfuscator

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

Empire client application

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Remote Code Execution Exploit for Citrix Application Delivery Controller and Citrix Gateway [ CVE-2019-19781 ]

WePWNise generates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and…