
scalpel
File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…

File carving and indexing tool for digital forensics, recovering files from disk images based on header/footer pattern matching, regular expressions,…

Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)

The Sigma command line interface based on pySigma

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

A python script developed to process Windows memory images based on triage type.

VBScript & VBA source-to-source deobfuscator with partial-evaluation

Lord Of Active Directory - automatic vulnerable active directory on AWS

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

DLL hijacking proof-of-concept that weaponizes Microsoft Defender's MpClient.dll to load Cobalt Strike, demonstrating LockBit-style defense evasion.

Minimal proof-of-concept remote access trojan in Go using libp2p rendezvous and pubsub for self-healing command-and-control over Linux and Windows…

C++ self-Injecting dropper based on various EDR evasion techniques.

Cloudflare Turnstile 绕过工具 | Cloudflare Bypass Tool based on SeleniumBase UC Mode | 支持 Mac/Windows/Linux

Kernel-mode filter driver that monitors ConDrv traffic to detect mimikatz execution in real-time, logging detection events via ETW for incident…

Windows kernel exploit leveraging an arbitrary read vulnerability combined with Superfetch to achieve elevation of privilege from low integrity.

A headless , scriptable, command-line based MITM proxy designed for network traffic interception, analysis, and modification on Windows systems.

Windows kernel exploit for CVE-2020-17057 using palette objects with dangling data pointers, targeting type isolation bypass for privilege escalation.

Proof-of-concept exploit for CVE-2024-49113 (LDAP Nightmare), a critical heap-based buffer overflow in Windows LDAP client (wldap32.dll). Includes a…

This is a plugin for the c# R.A.T server providing extension to android based phone systems