Kr0ff/PenDock
A script to build either Blackarch, Kali linux or ParrotOS Docker container which has the ability to provide desktop environment access either via X2Go or VNC
A script to build either Blackarch, Kali linux or ParrotOS Docker container which has the ability to provide desktop environment access either via X2Go or VNC
A PasteBin scrapper that doesnt rely on the PasteBin scrape API
Erebus is an Initial Access wrapper for the Mythic Command & Control Server. It converts shellcode into payloads specifically used for phishing and IA operations.
Various methods of executing shellcode
Enable full screen for linux VMs in vmware with open-vm-tools
Malware development
AdaptixFramework Extension Kit
🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications
Modules used by the Havoc Framework
:scream: A curated list of amazingly awesome OSINT
Retrieve information about breached accounts from "Combination Of Many Breaches" database (from proxynova.com)
This is a little experiment I want to start with. Basically ask claude to give a course on a github project. But basically I get a link to the github project, generate the course and then upload it as a git page. I'm just bored twin
Just a janky bash script with templated yaml files to deploy elasticEDR (elasticsearch + kibana) on a host for testing purposes
Hellokitty Ransomware Sourcecode leaked
Linux Sleep Obfuscation
Shellcode loader written in C with various AV/EDR bypassing features
Using the SystemFunction040 API to encrypt shellcode in memory and decrypt
A djb2 string hashing program which can be used to get the hash value of the name of an NTDLL function. Can be used with Hell's Gate or any of the *Gate variants
Shellcode execution by loading a "vulnerable" third-party module containing RWX section.
Tiger is v3 initial access payload in C
This a method of using WorkItem API to queue them to load a module. This version was modified to support string hashing via CRC32B.
Identify and restore temporary and backup text files from Notepad++
A list of payloads for SQL Injection testing
A simple tool to grab quickly pentest tools or similar from GitHub/Gitlab.
A terraform based project to automatically create a cloud environment for red team or phishing engagements
ForsHops
Kr0ff's blog