
DuplicateDump
Dumping LSASS with a duplicated handle from custom LSA plugin

Dumping LSASS with a duplicated handle from custom LSA plugin

SSH-based reverse shell management tool with native SCP/SFTP support, multiple transport protocols, Windows DLL generation, and fileless execution…

Parses Cortex XDR agent database lock files to extract agent settings, uninstall password hash/salt, and security exclusions for red team assessments…

A scanner that files with compromised or untrusted code signing certificates written in python.

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

Modular framework for Windows UAC bypass attacks and mitigation, featuring DLL hijacking, fileless execution, and real-time monitoring to detect and…

Generate an obfuscated DLL that will disable AMSI & ETW

A POC of a new “threadless” process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote…

Disassemble ANY files including .so (NDK, JNI), Windows PE(EXE, DLL, SYS, etc), linux binaries, libraries, and any other files such as pictures,…

CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking

pure-python implementation of MemoryModule technique to load dll and unmanaged exe entirely from memory

Automated DLL Sideloading Tool With EDR Evasion Capabilities

Windows implant that steals RDP credentials via API hooking (Detours) and DLL injection, capturing usernames and passwords to a file for red-team…

Windows privilege escalation discovery tool that parses Process Monitor boot logs to identify DLL hijacking, weak ACLs, and other elevation paths,…

Adaptive DLL hijacking / dynamic export forwarding

New version of RottenPotato as a C++ DLL and standalone C++ binary - no need for meterpreter or other tools.

PE loader with various shellcode injection techniques

This is a PoC for bypassing UAC using DLL hijacking and abusing the "Trusted Directories" verification.