This is your work, valued
chomp-scan. A scripted pipeline of tools to streamline the bug bounty/penetration test reconnaissance phase, so you can focus on chomping bugs.
393SleepyCrypt. A shellcode function to encrypt a running process image when sleeping.
338htbenum. A Linux enumeration script for Hack The Box
192SyscallPOC. Shellcode injection POC using syscalls.
116RubeusToCcache. A small tool to convert Base64-encoded .kirbi tickets from Rubeus into .ccache files for Impacket
75COM-Hijacking. An example of COM hijacking using a proxy DLL.
42hacker-checklist. Hacking with the power of checklists.
39SeasideBishop. A C port of b33f's UrbanBishop
38netntlm. A crappy hook on SpAcceptLsaModeContext that prints incoming auth attempts. WIP
37UnhookingPOC. A small commented POC for removing API hooks placed by AV/EDR.
34initial-scan. A tool for performing an initial information-gathering scan of websites for penetration tests.
24TokenStealingDriver. C++
24sri-check. A Burp Suite extension for identifying missing Subresource Integrity attributes.
13cookie-decrypter. A Burp Suite Professional extension for decrypting/decoding various types of cookies.
12ApiHashing. Replacing GetModuleHandle & GetProcAddress as a God
6csharptoolbox. PowerShell
4vim-snazzy. Elegant vim theme with bright colors.
3Ares. Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique
2COMThanasia. A set of programs for analyzing common vulnerabilities in COM
2MalwareApiLibrary. collection of apis used in malware development
2RecycledGate. Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll
2VX-API-1. Collection of various malicious functionality to aid in malware development
2LoadLibrary-GetProcAddress-Replacements. LoadLibrary() and GetProcAddress() Replacement Functions
2ShellcodeFluctuation. An in-memory evasion technique fluctuating shellcode memory protection between RW & RX and encrypting/decrypting contents
2RAII-types. Code to handle certain Windows types using the RAII paradigm
2inject-assembly. Inject .NET assemblies into an existing process
2ImprovedReflectiveDLLInjection. An improvement of the original reflective DLL injection technique by Stephen Fewer of Harmony Security
2NiCOFF. COFF and BOF Loader written in Nim
1TREVORspray. TREVORspray is a modular password sprayer with threading, clever proxying, loot modules, and more!
1No-Consolation. A BOF that runs unmanaged PEs inline
1ShellcodeStdio. An extensible framework for easily writing compiler optimized position independent x86 / x64 shellcode for windows platforms.
1Shoggoth. Shoggoth: Asmjit Based Polymorphic Encryptor
1DeathSleep. A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementing page protection changes during no execution.
1Hunt-Weird-ImageLoads. Small tool to play with IOCs caused by Imageload events
1NativeNtdllRemap. Remap ntdll.dll using only NTAPI functions with a suspended process
1Direct-NtCreateUserProcess. Call NtCreateUserProcess directly as normal.
1ShellcodeTemplate. An easily modifiable shellcode template for Windows x64/x86
1log.c. A simple logging library implemented in C99
1DllToShellCode. Fast Conversion Windows Dynamic Link Library To ShellCode
1Cookie-Graber-BOF. C or BOF file to extract WebKit master key to decrypt user cookie
1SysWhispers3. SysWhispers on Steroids - AV/EDR evasion via direct system calls.
1AceLdr. Cobalt Strike UDRL for memory scanner evasion.
1titanldr-ng. A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge years ago.
1phnt. Native API header files for the System Informer project.
1CreateProcess. A small PoC that creates processes in Windows
1sRDI. Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode
1APCLdr. Payload Loader With Evasion Features
1D1rkLdr. Shellcode Loader with Indirect Dynamic syscall Implementation , shellcode in MAC format, API resolving from PEB, Syscall calll and syscall instruction address resolving at run time
1StinkyLoader. It stinks
1SLAE64. Materials for PentesterAcademy SLAE64 Ccourse
1DarkLoadLibrary. LoadLibrary for offensive operations
1Hunt-Sleeping-Beacons. Aims to identify sleeping beacons
1log4j-scan. A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
1YouMayPasser. You shall pass
1segmentation-scan. Shell
1C-To-Shellcode-Examples. C
1