
Cronos
PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

Lord Of Active Directory - automatic vulnerable active directory on AWS

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

DLL hijacking proof-of-concept that weaponizes Microsoft Defender's MpClient.dll to load Cobalt Strike, demonstrating LockBit-style defense evasion.

Minimal proof-of-concept remote access trojan in Go using libp2p rendezvous and pubsub for self-healing command-and-control over Linux and Windows…

C++ self-Injecting dropper based on various EDR evasion techniques.

Windows kernel exploit leveraging an arbitrary read vulnerability combined with Superfetch to achieve elevation of privilege from low integrity.

Proof-of-concept exploit for CVE-2024-49113 (LDAP Nightmare), a critical heap-based buffer overflow in Windows LDAP client (wldap32.dll). Includes a…

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

Proof-of-concept exploit for PreAuth RCE in ManageEngine ServiceDesk Plus (CVE-2021-44077). Uploads and executes arbitrary Windows executables on…

Tool to exploit CVE-2018-13341 and recover hidden account password on Crestron devices

Cobalt Strike aggressor script implementing CVE-2020-0796 local privilege escalation via reflective DLL injection for Windows 10 and Server 1903/1909.

Embedded GRU neural network for real-time human behavior verification via mouse movement analysis, detecting automated analysis systems, sandboxes,…

A Bind Shell Using the Fax Service and a DLL Hijack

Automated Persistence and Lateral Movement using GCP Patch Management

Python framework for generating polymorphic Windows executables with multi-layer RC4 encryption, junkcode injection, and binary metadata spoofing to…

Generates initial access payloads abusing AddInProcess.exe via .NET deserialization, supporting HTA, VBA, JS, and CHM templates for in-memory code…

Open source pre-operation C2 server based on python and powershell