This is your work, valued

Solomon Sklash

Expert
@SolomonSklash

Offensive security.

chomp-scan. A scripted pipeline of tools to streamline the bug bounty/penetration test reconnaissance phase, so you can focus on chomping bugs.

393

SleepyCrypt. A shellcode function to encrypt a running process image when sleeping.

338

htbenum. A Linux enumeration script for Hack The Box

192

SyscallPOC. Shellcode injection POC using syscalls.

116

RubeusToCcache. A small tool to convert Base64-encoded .kirbi tickets from Rubeus into .ccache files for Impacket

75

COM-Hijacking. An example of COM hijacking using a proxy DLL.

42

hacker-checklist. Hacking with the power of checklists.

39

SeasideBishop. A C port of b33f's UrbanBishop

38

netntlm. A crappy hook on SpAcceptLsaModeContext that prints incoming auth attempts. WIP

37

UnhookingPOC. A small commented POC for removing API hooks placed by AV/EDR.

34

initial-scan. A tool for performing an initial information-gathering scan of websites for penetration tests.

24

TokenStealingDriver. C++

24

sri-check. A Burp Suite extension for identifying missing Subresource Integrity attributes.

13

cookie-decrypter. A Burp Suite Professional extension for decrypting/decoding various types of cookies.

12

ApiHashing. Replacing GetModuleHandle & GetProcAddress as a God

6

csharptoolbox. PowerShell

4

vim-snazzy. Elegant vim theme with bright colors.

3

Ares. Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique

2

COMThanasia. A set of programs for analyzing common vulnerabilities in COM

2

MalwareApiLibrary. collection of apis used in malware development

2

RecycledGate. Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll

2

VX-API-1. Collection of various malicious functionality to aid in malware development

2

LoadLibrary-GetProcAddress-Replacements. LoadLibrary() and GetProcAddress() Replacement Functions

2

ShellcodeFluctuation. An in-memory evasion technique fluctuating shellcode memory protection between RW & RX and encrypting/decrypting contents

2

RAII-types. Code to handle certain Windows types using the RAII paradigm

2

inject-assembly. Inject .NET assemblies into an existing process

2

ImprovedReflectiveDLLInjection. An improvement of the original reflective DLL injection technique by Stephen Fewer of Harmony Security

2

NiCOFF. COFF and BOF Loader written in Nim

1

TREVORspray. TREVORspray is a modular password sprayer with threading, clever proxying, loot modules, and more!

1

No-Consolation. A BOF that runs unmanaged PEs inline

1

ShellcodeStdio. An extensible framework for easily writing compiler optimized position independent x86 / x64 shellcode for windows platforms.

1

Shoggoth. Shoggoth: Asmjit Based Polymorphic Encryptor

1

DeathSleep. A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementing page protection changes during no execution.

1

Hunt-Weird-ImageLoads. Small tool to play with IOCs caused by Imageload events

1

NativeNtdllRemap. Remap ntdll.dll using only NTAPI functions with a suspended process

1

Direct-NtCreateUserProcess. Call NtCreateUserProcess directly as normal.

1

ShellcodeTemplate. An easily modifiable shellcode template for Windows x64/x86

1

log.c. A simple logging library implemented in C99

1

DllToShellCode. Fast Conversion Windows Dynamic Link Library To ShellCode

1

Cookie-Graber-BOF. C or BOF file to extract WebKit master key to decrypt user cookie

1

SysWhispers3. SysWhispers on Steroids - AV/EDR evasion via direct system calls.

1

AceLdr. Cobalt Strike UDRL for memory scanner evasion.

1

titanldr-ng. A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge years ago.

1

phnt. Native API header files for the System Informer project.

1

CreateProcess. A small PoC that creates processes in Windows

1

sRDI. Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

1

APCLdr. Payload Loader With Evasion Features

1

D1rkLdr. Shellcode Loader with Indirect Dynamic syscall Implementation , shellcode in MAC format, API resolving from PEB, Syscall calll and syscall instruction address resolving at run time

1

StinkyLoader. It stinks

1

SLAE64. Materials for PentesterAcademy SLAE64 Ccourse

1

DarkLoadLibrary. LoadLibrary for offensive operations

1

Hunt-Sleeping-Beacons. Aims to identify sleeping beacons

1

log4j-scan. A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

1

YouMayPasser. You shall pass

1

segmentation-scan. Shell

1

C-To-Shellcode-Examples. C

1