This is your work, valued

USA

White Knight Labs

Expert
@WKL-Sec

HiddenDesktop. HVNC for Cobalt Strike

1.3k

Malleable-CS-Profiles. A list of python tools to help create an OPSEC-safe Cobalt Strike profile.

537

dcomhijack. Lateral Movement Using DCOM and DLL Hijacking

327

LayeredSyscall. Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR hooks in Windows.

312

GregsBestFriend. GregsBestFriend process injection code created from the White Knight Labs Offensive Development course

207

WMIExec. Set of python scripts which perform different ways of command execution via WMI protocol.

168

Winsocky. Winsocket for Cobalt Strike.

105

Warmer. Selenium-based Python script to automate sending emails to warm up your sender reputation and improve email deliverability

98

FuncAddressPro. A stealthy, assembly-based tool for secure function address resolution, offering a robust alternative to GetProcAddress.

75

slack-udc2. Cobalt Strike UDC2 implementation that provides an Slack C2 channel

69

StackMask. A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.

68

Illicit-Services-Enum-Script. Python

68

KnAIght. A modern, scalable web application for obfuscating prompts to bypass AI detection systems.

29

docker-cobaltstrike. Docker container for running CobaltStrike 4.7 and above

25

OpenBOF. A community maintained repository of Beacon Object Files (BOFs) for red team operations, research, and education. Our goal is to provide a centralized collection of high quality BOFs, making them easier to discover, use, and contribute to.

22

wkl-gophish. WKl Gophish based on Sneaky Gophish

12

WKL-Passwords. Wordlist, rules and masks from White Knight Labs

8

async-callback-thread-injection. ODPC / White Knight Labs: educational async callback thread injection—C# demos stage OpenProcess→VirtualAllocEx→WPM via EnumUILanguagesA/EnumSystemLocalesA, then CreateRemoteThread or NtCreateThreadEx (CallbackInject / CallbackInjectNested).

4

windows-server-2025-x64-calc-shellcode. Position-independent x64 Windows shellcode that dynamically resolves WinExec via PEB walking and export hashing, with a loader-patched ExitThread epilogue for clean thread termination. Built for White Knight Labs training courses.

4

okta-mfa-check. OKTA MFA Check using Python and Selenium. Tool checks valid OKTA accounts to determine which MFA options are enabled/disabled

3