Tylous/SniffAir
A framework for wireless pentesting.
A framework for wireless pentesting.
SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.
Freeze.rs is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls written in RUST
Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs
Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods
Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing programmatical access in the VBA object environment to load, decrypt and execute shellcode.
ScareCrow - Payload creation framework designed around EDR bypass.
A password guessing tool that targets the Kerberos and LDAP services within the Windows Active Directory environment.
A tool for generating fake code signing certificates or signing real ones
A framework for stealthy domain reconnaissance
A unique technique to execute binaries from a password protected zip
FaceDancer is an exploitation tool aimed at creating hijackable, proxy-based DLLs by taking advantage of COM-based system DLL image loading
A Post-exploitation Toolset for Interacting with the Microsoft Graph API
A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.
Tunnel TCP connections through a file
HVNC based on RustDesk
HTML smuggling is not an evil, it can be useful
Automated Brute-Force Login Attacks Against EAP Networks.
My collection of dockerfiles
Print Spooler Named Pipe Impersonation for Cobalt Strike
cobalt strike tools
Ready to go Phishing Platform
A PoC that packages payloads into output containersb to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats. Supports: ZIP, 7zip, PDF, ISO, IMG, CAB, VHD, VHDX
Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.
A tool to verify and create PE Checksums for Portable Executable (PE) files.
Ansible playbook to deploy a phishing engagement
The idea is to collect all the C# projects that are Sharp{Word} that can be used in Cobalt Strike as execute assembly command.
InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assembly execution as an alternative to Cobalt Strikes traditional fork and run execute-assembly module
SysWhispers on Steroids - AV/EDR evasion via direct system calls.