
WMImplant
PowerShell-based RAT using WMI for remote command execution, lateral movement, and C2 communication. Enables file operations, process management,…

PowerShell-based RAT using WMI for remote command execution, lateral movement, and C2 communication. Enables file operations, process management,…

Windows kernel exploit for CVE-2020-17057 using palette objects with dangling data pointers, targeting type isolation bypass for privilege escalation.

Command-line and Python debugger for instrumenting and modifying native software behavior on Windows and Linux.

Proof-of-concept exploit for PreAuth RCE in ManageEngine ServiceDesk Plus (CVE-2021-44077). Uploads and executes arbitrary Windows executables on…

Python framework for generating polymorphic Windows executables with multi-layer RC4 encryption, junkcode injection, and binary metadata spoofing to…

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

PoC memory injection detection agent based on ETW, for offensive and defensive research purposes

A python script developed to process Windows memory images based on triage type.

a tool to manipulate dcc(domain cached credentials) in windows registry, based mainly on the work of mimikatz and impacket

Cobalt Strike aggressor script implementing CVE-2020-0796 local privilege escalation via reflective DLL injection for Windows 10 and Server 1903/1909.

Generates malicious DOCX documents exploiting CVE-2021-40444 (Microsoft Office RCE) with a hosted server for DLL payload delivery, based on…

DLL hijacking proof-of-concept that weaponizes Microsoft Defender's MpClient.dll to load Cobalt Strike, demonstrating LockBit-style defense evasion.

A simple python tool based on Impacket that tests servers for various known NTLM vulnerabilities

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing

Kernel-mode filter driver that monitors ConDrv traffic to detect mimikatz execution in real-time, logging detection events via ETW for incident…

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

Proof-of-concept demonstrating CVE-2020-0601 by crafting a rogue root CA and signed certificate that bypasses Windows certificate chain validation.