TheWover's Stars
flipperdevices/flipperzero-firmware
Flipper Zero firmware source code
RedSiege/EyeWitness
EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.
p0dalirius/Coercer
A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.
flipperdevices/Flipper-Android-App
Android Mobile app to rule all Flipper's family
microsoft/win32metadata
Tooling to generate metadata for Win32 APIs in the Windows SDK.
WKL-Sec/HiddenDesktop
HVNC for Cobalt Strike
med0x2e/SigFlip
SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.
arget13/DDexec
A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.
diversenok/TokenUniverse
An advanced tool for working with access tokens and Windows security policy.
evild3ad/MemProcFS-Analyzer
MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
ricardojoserf/NativeDump
Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)
thefLink/Hunt-Sleeping-Beacons
Aims to identify sleeping beacons
l4rm4nd/LinkedInDumper
Python 3 script to dump/scrape/extract company employees from LinkedIn API
Meowmycks/LetMeowIn
A sophisticated, covert Windows-based credential dumper using C++ and MASM x64.
0xEr3bus/PoolPartyBof
A beacon object file implementation of PoolParty Process Injection Technique.
securifybv/Visual-Studio-BOF-template
A Visual Studio template used to create Cobalt Strike BOFs
0xcpu/WinAltSyscallHandler
Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999
eversinc33/BouncyGate
Indirect Syscalls: HellsGate in Nim, but making sure that all syscalls go through NTDLL (as in RecycledGate).
rasta-mouse/CsWhispers
Source generator to add D/Invoke and indirect syscall methods to a C# project.
ipSlav/DirtyCLR
An App Domain Manager Injection DLL PoC on steroids
repnz/apc-research
APC Internals Research Code
jsecurity101/ETWInspector
vxCrypt0r/AMSI_VEH
A Powershell AMSI Bypass technique via Vectored Exception Handler (VEH). This technique does not perform assembly instruction patching, function hooking or Import Address Table (IAT) modification.
DownWithUp/CallMon
CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers
ControlCompass/ControlCompass.github.io
Pointing cybersecurity teams to thousands of detection rules and offensive security tests aligned with common attacker techniques
outflanknl/external_c2
POC for Cobalt Strike external C2
klezVirus/RpcProxyInvoke
Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar
sadshade/veeam-creds
Collection of scripts to retrieve stored passwords from Veeam Backup
avast/pe_tools
A cross-platform Python toolkit for parsing/writing PE files.
zimnyaa/LEOPARDSEAL
A simple Linux in-memory .so loader