
ALPC-Enumerator
A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

This is the tool to dump the LSASS process on modern Windows 11

A light-weight first-stage C2 implant written in Nim (and Rust).

Remote Administration Tool for Windows

Windows privilege escalation exploit abusing a TOCTOU in Code Integrity to bypass Protected Process Light, execute as WinTcb-Light, and dump…

Windows kernel driver that removes Process Protection (PP) and Process Protection Light (PPL).

Cobalt Strike BOF that exploits a Windows Protected Process Light bypass to dump protected processes, enabling credential access from LSASS.

Execute PowerShell code at the antimalware-light protection level.

iTop < 2.7.6 - (Authenticated) Remote command execution

Proof-of-concept C exploit that runs a DLL with WinTcb-Light protection from userland, demonstrating a Windows privilege-escalation primitive and…

A front-end JavaScript toolkit for creating DNS rebinding attacks.

A network packet forensics tool for SSH

Lilith - Foundational reverse engineering resource for cybersecurity entrepreneurs in C++

Lightweight RAT providing silent remote command-line access, hidden file download/execution, and persistence mechanisms for Windows systems.…