This is your work, valued
AzureAD-Attack-Defense. This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.
★ 2.5kSOAPy. SOAPy is a Proof of Concept (PoC) tool for conducting offensive interaction with Active Directory Web Services (ADWS) through a SOCKS5 proxy.
★ 212flaregun. 🔥 Rotating proxy network on Cloudflare Workers. Deploy, rotate, fire.
★ 50DRSAT. Disconnected RSAT - A method of running Group Policy Manager, Certificate Authority and Certificate Templates MMC snap-ins from non-domain joined machies
★ 312fluffy-barnacle. Disposable, ephemeral network infrastructure powered by GitHub Codespaces.
★ 124heretic. Fully automatic censorship removal for language models
★ 27kimpeccable. The design language that makes your AI harness better at design.
★ 54kagency-agents. A complete AI agency at your fingertips - From frontend wizards to Reddit community ninjas, from whimsy injectors to reality checkers. Each agent is a specialized expert with personality, processes, and proven deliverables.
★ 138kMiroFish. A Simple and Universal Swarm Intelligence Engine, Predicting Anything. 简洁通用的群体智能引擎,预测万物
★ 70kpromptfoo. Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command line and CI/CD integration. Used by OpenAI and Anthropic.
★ 24kOpenViking. Self-evolving Context Database for AI Agents. Unify Agent Memory, Knowledge RAG and Skills.
★ 28khydra. Multi-agent AI orchestration system
★ 18processhacker-mcp. your ai debugger, vibe hacking tool
★ 50dcsync-bof. dcsync bof
★ 54claude-ctrl. The Systems Thinker's Deterministic Claude Code Control Plane
★ 190ECC. The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
★ 237kdumpguard_bof. Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.
★ 220TaskHound. Tool to enumerate privileged Scheduled Tasks on Remote Systems
★ 312extloader. A chromium extension exploitation toolkit
★ 26stillepost. Using Chromium-based browsers as a proxy for C2 traffic.
★ 156ChromeAlone. A tool to transform Chromium browsers into a C2 Implant
★ 594Misconfiguration-Manager. Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive and hardening guidance.
★ 1.2kDumpGuard. Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.
★ 720Inline-EA. Cobalt Strike BOF for evasive .NET assembly execution
★ 323BitlockMove. Lateral Movement via Bitlocker DCOM interfaces & COM Hijacking
★ 459VPK. Vast.ai Password Kracking
★ 96TokenPhisher. JavaScript
★ 26rspy. rust port of pspy with support for process monitoring over dbus
★ 38byor. Go
★ 166RiscyWorkshop. Payload Obfuscation for Red Teams workshop materials
★ 88defendnot. An even funnier way to disable windows defender. (through WSC api)
★ 3.6ksmbcrawler. smbcrawler is no-nonsense tool that takes credentials and a list of hosts and 'crawls' (or 'spiders') through those shares
★ 189BOF-entra-authcode-flow. Beacon Object File (BOF) to obtain Entra tokens via authcode flow.
★ 140proxyblob. SOCKS5 proxy tool that uses Azure Storage services as a means of communication.
★ 361goexec. Windows remote execution multitool
★ 807awesome-bof. 🧠 The ultimate resource for finding Beacon Object Files (BOFs).
★ 150PMD. C++
★ 159waiting_thread_hijacking. Waiting Thread Hijacking - injection by overwriting the return address of a waiting thread
★ 265SuperMega. Stealthily inject shellcode into an executable
★ 477DSViper. This is for Ethical Use only. The default automated binaries created are all burned. I have added the script to the repo to modify certain signatures and it will still work.
★ 451koneko. Robust Cobalt Strike shellcode loader with multiple advanced evasion features
★ 206myAwesome.
★ 251TrickDump. Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!
★ 565utls. Fork of the Go standard TLS library, providing low-level access to the ClientHello for mimicry purposes.
★ 2.5kspoofed-round-tripper. A Go's http.RoundTripper implementation that provides a wrapper for tls-client and leverages uTLS to spoof TLS fingerprints (JA3, JA4, HTTP/2 Akamai, etc) of mainstream browsers for use in different HTTP client libraries (like resty) to bypass Cloudflare or other firewalls.
★ 53awesome-injection. Centralized resource for listing and organizing known injection techniques and POCs
★ 708early_cascade_inj_rs. early cascade injection PoC based on Outflanks blog post, in rust
★ 64AV-EDR-Lab-Environment-Setup. AV/EDR Lab environment setup references to help in Malware development
★ 469Hooker. C
★ 109LsassReflectDumping. This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created, it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process
★ 220tun2socks. tun2socks - powered by gVisor TCP/IP stack
★ 5.4kASRepCatcher. Make everyone in your VLAN ASRep roastable
★ 268Red-Teaming-Toolkit. This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
★ 11kRemoteKrbRelay. Remote Kerberos Relay made easy! Advanced Kerberos Relay Framework
★ 650frameless-bitb. A new approach to Browser In The Browser (BITB) without the use of iframes, allowing the bypass of traditional framebusters implemented by login pages like Microsoft and the use with Evilginx.
★ 455Voidgate. A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by performing on-the-fly decryption of individual encrypted assembly instructions, thus rendering memory scanners useless for that specific memory page.
★ 598Evilginx-Phishing-Infra-Setup. Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs
★ 598reconic. A Powerful Network Reconnaissance Tool for Security Professionals
★ 107edr-internals. Tools for analyzing EDR agents
★ 279HSC24RedTeamInfra. Slides and Codes used for the workshop Red Team Infrastructure Automation
★ 193Invoke-DumpMDEConfig. PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )
★ 155File-Tunnel. Tunnel TCP connections through a file
★ 1.1kProxy-DLL-Loads. A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.
★ 411GraphSpy. Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI
★ 1.4kAD_Miner. AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses
★ 1.5kChecklists. Red Teaming & Pentesting checklists for various engagements
★ 2.7kawesome-list. Cybersecurity oriented awesome list
★ 3.9k