
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

A basic emulation of an "RPC Backdoor"

Various ways to execute shellcode

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

AutoPoC Generator HoneyPoC


🌴Linux、macOS、Windows Kernel privilege escalation vulnerability collection, with compilation environment, demo GIF map, vulnerability details,…

A third-party Gopher Assassin for the Havoc Framework.

A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Kill AV/EDR leveraging BYOVD attack

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in…

Documents Exfiltration project for fun and educational purposes

C++ self-Injecting dropper based on various EDR evasion techniques.