Pinned Repositories
dcomhijack
Lateral Movement Using DCOM and DLL Hijacking
FuncAddressPro
A stealthy, assembly-based tool for secure function address resolution, offering a robust alternative to GetProcAddress.
GregsBestFriend
GregsBestFriend process injection code created from the White Knight Labs Offensive Development course
HiddenDesktop
HVNC for Cobalt Strike
LayeredSyscall
Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR hooks in Windows.
Malleable-CS-Profiles
A list of python tools to help create an OPSEC-safe Cobalt Strike profile.
StackMask
A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.
Warmer
Selenium-based Python script to automate sending emails to warm up your sender reputation and improve email deliverability
Winsocky
Winsocket for Cobalt Strike.
WMIExec
Set of python scripts which perform different ways of command execution via WMI protocol.
WKL-Sec's Repositories
WKL-Sec/HiddenDesktop
HVNC for Cobalt Strike
WKL-Sec/Malleable-CS-Profiles
A list of python tools to help create an OPSEC-safe Cobalt Strike profile.
WKL-Sec/dcomhijack
Lateral Movement Using DCOM and DLL Hijacking
WKL-Sec/LayeredSyscall
Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR hooks in Windows.
WKL-Sec/GregsBestFriend
GregsBestFriend process injection code created from the White Knight Labs Offensive Development course
WKL-Sec/WMIExec
Set of python scripts which perform different ways of command execution via WMI protocol.
WKL-Sec/Winsocky
Winsocket for Cobalt Strike.
WKL-Sec/FuncAddressPro
A stealthy, assembly-based tool for secure function address resolution, offering a robust alternative to GetProcAddress.
WKL-Sec/Warmer
Selenium-based Python script to automate sending emails to warm up your sender reputation and improve email deliverability
WKL-Sec/StackMask
A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.
WKL-Sec/Illicit-Services-Enum-Script
WKL-Sec/docker-cobaltstrike
Docker container for running CobaltStrike 4.7 and above
WKL-Sec/WKL-Passwords
Wordlist, rules and masks from White Knight Labs
WKL-Sec/wkl-gophish
WKl Gophish based on Sneaky Gophish
WKL-Sec/okta-mfa-check
OKTA MFA Check using Python and Selenium. Tool checks valid OKTA accounts to determine which MFA options are enabled/disabled