
DLLirant
Automates DLL hijacking and DLL proxying research on Windows binaries by analyzing PE imports, generating proxy DLLs, and producing proof-of-concept…

Automates DLL hijacking and DLL proxying research on Windows binaries by analyzing PE imports, generating proxy DLLs, and producing proof-of-concept…

.NET command and control framework with dynamic C# compilation, encrypted key exchange, and multi-user collaboration for red team operations.…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

In-memory Java stager that downloads, compiles, and executes arbitrary Java payloads over HTTP, enabling AV evasion and remote code execution for red…

In-memory implant framework for Java and ASP.NET webshells with AES-encrypted communication, dynamic payload loading, and session-based execution for…

C++ DLL template generator that hides exported functions from the filesystem export directory while reconstructing it at runtime to enable dynamic…

Intercept Windows Named Pipes communication using Burp or similar HTTP proxy tools

High-performance Rust HTTP/HTTPS proxy with active defense: rate limiting, reputation-based access, WAF (anti-bot, anti-injection, path protection),…

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

Jupyter notebooks and scripts for testing and analyzing OAuth 2.0 grants and OpenID Connect authentication flows, including certificate auth and JWT…

Proof-of-concept exploit for CVE-2023-27532 in Veeam Backup and Replication that abuses an unsecured API endpoint to extract credentials from the…

Remote PowerShell-based security audit tool for CyberArk PAM platforms. Performs CIS benchmark compliance, CVE checks, blackbox testing, and network…