Pinned Repositories
AzTokenFinder
AzureC2Relay
AzureC2Relay is an Azure Function that validates and relays Cobalt Strike beacon traffic by verifying the incoming requests based on a Cobalt Strike Malleable C2 profile.
BAADTokenBroker
DLLHound
Find potential DLL Sideloads on your windows computer
ForgeCert
"Golden" certificates
FunctionalC2
A small POC of using Azure Functions to relay communications. Feel free to add additional functionality beyond this POC!
gocheck
Because AV evasion should be easy.
Invoke-DLLClone
Koppeling x Metatwin x LazySign
ysoserial.net-docker
ysoserial.net docker image
PaulzePirate's Repositories
PaulzePirate/ysoserial.net-docker
ysoserial.net docker image
PaulzePirate/AzTokenFinder
PaulzePirate/AzureC2Relay
AzureC2Relay is an Azure Function that validates and relays Cobalt Strike beacon traffic by verifying the incoming requests based on a Cobalt Strike Malleable C2 profile.
PaulzePirate/BAADTokenBroker
PaulzePirate/DLLHound
Find potential DLL Sideloads on your windows computer
PaulzePirate/ForgeCert
"Golden" certificates
PaulzePirate/FunctionalC2
A small POC of using Azure Functions to relay communications. Feel free to add additional functionality beyond this POC!
PaulzePirate/gocheck
Because AV evasion should be easy.
PaulzePirate/Invoke-DLLClone
Koppeling x Metatwin x LazySign
PaulzePirate/IORI_Loader
UUID shellcode Loader with dynamic indirect syscall implementation, syscall number/instruction get resolved dynamicaly at runtime, and the syscall number/instruction get unhooked using Halosgate technique. Function address get resolved from the PEB by offsets and comparaison by hashes
PaulzePirate/NovaLdr
Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)
PaulzePirate/RecycledInjector
Native Syscalls Shellcode Injector
PaulzePirate/TeamsImplant
PaulzePirate/TokenUniverse
An advanced tool for working with access tokens and Windows security policy.
PaulzePirate/UUIDRegistryShellcode
Write and Hide each UUID in the char* array of UUIDS shellcode in a registry key value location as REG_SZ (the location could be different from the other), then retrieve them and assemble them in UUIDs char* array shellcode and Run it
PaulzePirate/TokenSmith
TokenSmith generates Entra ID access & refresh tokens on offensive engagements. It is suitable for both covert adversary simulations and penetration tests with the tokens generated working out of the box with many popular Azure post exploitation tools.