Skip to content
Change the repository type filter

All

    Repositories list

    • A Go implementation of Cobalt Strike style BOF/COFF loaders.
      Go
      Apache License 2.0
      27300Updated Oct 17, 2024Oct 17, 2024
    • nanodump

      Public
      Dump LSASS like you mean it
      C
      Apache License 2.0
      2381101Updated Aug 13, 2024Aug 13, 2024
    • Situational Awareness commands implemented using Beacon Object Files
      C
      GNU General Public License v2.0
      216802Updated Aug 11, 2024Aug 11, 2024
    • armory

      Public
      The Official Sliver Armory
      1282170Updated Jul 25, 2024Jul 25, 2024
    • C
      GNU General Public License v2.0
      21300Updated Jun 25, 2024Jun 25, 2024
    • C
      GNU General Public License v2.0
      127600Updated Jun 21, 2024Jun 21, 2024
    • Modules used by the Havoc Framework
      C
      57100Updated Jun 12, 2024Jun 12, 2024
    • A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.
      C
      192801Updated Jun 1, 2024Jun 1, 2024
    • Lateral Movement via the .NET Profiler
      C++
      17000Updated May 30, 2024May 30, 2024
    • Rubeus

      Public
      Trying to tame the three-headed dog.
      C#
      Other
      778200Updated May 20, 2024May 20, 2024
    • mimikatz

      Public
      A little tool to play with Windows security
      C
      3.7k100Updated May 17, 2024May 17, 2024
    • A self-hosted Armory implementation.
      Go
      GNU General Public License v3.0
      01210Updated May 7, 2024May 7, 2024
    • Utilities for building CPython for the WASI platform
      C
      Apache License 2.0
      14000Updated May 1, 2024May 1, 2024
    • kerbrute

      Public
      A tool to perform Kerberos pre-auth bruteforcing
      Go
      Apache License 2.0
      415000Updated Apr 10, 2024Apr 10, 2024
    • Sliver SDK
      Go
      GNU General Public License v3.0
      0600Updated Apr 5, 2024Apr 5, 2024
    • BOF implementation of @_EthicalChaos_'s ThreadlessInject project. A novel process injection technique with no thread creation, released at BSides Cymru 2023.
      C
      MIT License
      52000Updated Apr 4, 2024Apr 4, 2024
    • An all-in-one Cobalt Strike BOF to patch, check and revert AMSI and ETW for x64 process. Both syscalls and dynamic resolve versions are available.
      C
      Apache License 2.0
      18000Updated Apr 4, 2024Apr 4, 2024
    • SCShell

      Public
      Fileless lateral movement tool that relies on ChangeServiceConfigA to run command
      C
      236100Updated Apr 4, 2024Apr 4, 2024
    • PowerShell rebuilt in C# for Red Teaming purposes
      C#
      BSD 3-Clause "New" or "Revised" License
      136200Updated Apr 4, 2024Apr 4, 2024
    • SQLRecon

      Public
      A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.
      C#
      BSD 3-Clause "New" or "Revised" License
      113100Updated Apr 2, 2024Apr 2, 2024
    • SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.
      C#
      Other
      207000Updated Apr 2, 2024Apr 2, 2024
    • C# Data Collector for BloodHound
      C#
      GNU General Public License v3.0
      165100Updated Apr 2, 2024Apr 2, 2024
    • Seatbelt

      Public
      Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
      C#
      Other
      685300Updated Apr 2, 2024Apr 2, 2024
    • SharpSCCM

      Public
      A C# utility for interacting with SCCM
      C#
      GNU General Public License v3.0
      83100Updated Apr 2, 2024Apr 2, 2024
    • Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu, and KernelCTF. The success rate is 99.4% in KernelCTF images.
      C
      MIT License
      297200Updated Mar 27, 2024Mar 27, 2024
    • azbelt

      Public archive
      AAD related enumeration in Nim
      Nim
      MIT License
      7300Updated Sep 7, 2023Sep 7, 2023
    • hashdump

      Public
      Dump Windows SAM hashes
      Go
      GNU General Public License v3.0
      24010Updated Aug 9, 2023Aug 9, 2023
    • C++
      MIT License
      40200Updated Jun 27, 2023Jun 27, 2023
    • C++ WinRM API sliver extension
      C++
      0800Updated Jun 27, 2023Jun 27, 2023
    • Certify

      Public
      Active Directory certificate abuse.
      C#
      Other
      205300Updated Jun 22, 2023Jun 22, 2023