northrenghost's Stars
monoxgas/sRDI
Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode
vxunderground/VX-API
Collection of various malicious functionality to aid in malware development
eladshamir/Internal-Monologue
Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS
Invoke-IR/PowerForensics
PowerForensics provides an all in one platform for live disk forensic analysis
klezVirus/SysWhispers3
SysWhispers on Steroids - AV/EDR evasion via direct system calls.
MichaelKoczwara/Awesome-CobaltStrike-Defence
Defences against Cobalt Strike
boku7/BokuLoader
A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!
GhostPack/SharpDPAPI
SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.
med0x2e/GadgetToJScript
A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA based scripts.
FuzzySecurity/StandIn
StandIn is a small .NET35/45 AD post-exploitation toolkit
ail-project/ail-framework
AIL framework - Analysis Information Leak framework
ajpc500/BOFs
Collection of Beacon Object Files
WithSecureLabs/CallStackSpoofer
A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)
Arno0x/ShellcodeWrapper
Shellcode wrapper with encryption for multiple target languages
mgeeky/ElusiveMice
Cobalt Strike User-Defined Reflective Loader with AV/EDR Evasion in mind
Cracked5pider/KaynStrike
UDRL for CS
pwn1sher/frostbyte
FrostByte is a POC project that combines different defense evasion techniques to build better redteam payloads
NetSPI/DAFT
DAFT: Database Audit Framework & Toolkit
0x6d696368/ghidra_scripts
Ghidra scripts such as a RC4 decrypter, Yara search, stack string decoder, etc.
klezVirus/NimlineWhispers3
A tool for converting SysWhispers3 syscalls for use with Nim projects
djhohnstein/cliProxy
Proxy Unix applications in the terminal
proxb/PoshPrivilege
Manage user privileges on a local machine or view applied privileges on local or remote system
nyxgeek/guestlist
tool for identifying guest relationships between companies
zyn3rgy/ClickonceHunter
Golang search engine scraper intended for identification of published ClickOnce deployments
nyxgeek/teamstracker
using graph proxy to monitor teams user presence
Lookyloo/PlaywrightCapture
Capture a URL with Playwright
kyleavery/Multi-Stage-Mythic
djhohnstein/HookDetector
Playing with PE's and Building Structures by Hand
leechristensen/TribesRebirth
ASkyeye/Mangle
Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs