This is your work, valued
rbcd-attack. Kerberos Resource-Based Constrained Delegation Attack from Outside using Impacket
645dll-hijack-by-proxying. Exploiting DLL Hijacking by DLL Proxying Super Easily
563pwn-hisilicon-dvr. Python
384ad-honeypot-autodeploy. Deploy a small, intentionally insecure, vulnerable Windows Domain for RDP Honeypot fully automatically.
259serviceDetector. Detect whether a service is installed (blindly) and/or running (if exposing named pipes) on a remote machine without using local admin privileges.
241usbgadget-tool. Dumb USB HID gadget creator for Android (for triggering device driver install on Windows for LPE)
150stager_libpeconv. A basic meterpreter protocol stager using the libpeconv library by hasherezade for reflective loading
85smbmap. SMBMap is a handy SMB enumeration tool - here with Kerberos support
73SharpStay. .NET project for installing Persistence
63hs-dvr-telnet. open telnet port on modern HiSilicon devices
56log4shell-vulnerable-app. A Basic Java Application Vulnerable to the Log4Shell RCE
41PowerLessShell. Run PowerShell command without invoking powershell.exe
36CVE-2021-1675. C# and Impacket implementation (here with Kerberos auth support) of PrintNightmare CVE-2021-1675/CVE-2021-34527
29ctfs. some example ctf writeups
27azure-function-proxy. basic proxy as an azure function serverless app
17PetitPotam. PetitPotam fork with Kerberos support in the impacket script
17linkedin-auth-bypass. browse linkedin profiles without a registered account
15kali-rpi-luks-crypt. Full disk encryption for Kali on Raspberry using LUKS
15malicious-service. Minimal Windows Service Template for demonstrating privilege escalation via weak service executable permissions
14impacket. Impacket is a collection of Python classes for working with network protocols.
13smtp2slack4qnap. Compact SMTP to HTTP Gateway (targeting Slack for QNAP-NAS notifications)
12NoteThief. Grab unsaved Notepad contents with a Beacon Object File
11malicious-hisilicon-scripts. Materials from my older (2018) HiSilicon research
10Bundesnachrichtendienst. reversing / malware analysis recruitment challenge for German Federal Intelligence
8SharpShot. Trivial .NET desktop capturing for Red Team operations
6issuu-dl. download pdf from issuu.com
6gcstar-win32. standalone executable built from GCstar Perl release
5oauth-mitmproxy. oauth refresh_token client in mitmproxy
5steganography. Simple C++ Image Steganography tool to encrypt and hide files insde images using Least-Significant-Bit encoding.
5lineageos-bullhead-build. Unofficial LineageOS builds for Google Nexus 5X "bullhead" devices
5zphisher. An automated phishing tool with 30+ templates.
5remotethermo. remotethermo.com API test
4CVE-2020-1472. Test tool for CVE-2020-1472
3nmap-http-screenshot. take screenshots of http services from an nmap xml output
3azure-function-proxy-ng. Azure Function as a Reverse Proxy (e.g. for C2 ;) )
3railfence. a simple python implementation of the Rail Fence cipher (with offset support)
3sliver. Adversary Emulation Framework
3Powershell-PostExploitation. Scripts created to help with post exploitation of a Windows host
2wifipem. automated tool for extracting RADIUS public certificates from pcap files and live captures
2burp-Base64PostRequest. Burp Extension: Base64 decode / encode POST request data
2prosmart-mqtt. Minimal proSmart - MQTT Gateway
2android-keyboard-gadget. Convert your Android device into USB keyboard/mouse, control your PC from your Android device remotely, including BIOS/bootloader.
2DeviceGuardBypasses. A repository of some of my Windows 10 Device Guard Bypasses
2NetLoader. Loads any C# binary in mem, patching AMSI + ETW.
2riemann-nonconvex. Simulation of a totally asymmetric attractive interacting particle system
2sencor-bluetooth. Sample development Python scripts for reading data from the Sencor SWS 500 Outdoor Thermo/Humidity Meter Bluetooth LE device.
2tensorflow-captcha-solver. 🎲 Solve image based captchas using Tensorflow neural networks
1MsgKit. A .NET library to make MSG files without the need for Outlook
1adduser. Programmatically create an administrative user under Windows
1mvt. MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.
1home-assistant-core. :house_with_garden: Open source home automation that puts local control and privacy first.
1inceptor. Template-Driven AV/EDR Evasion Framework
1VulnerableDrivers. Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)
1KrbRelay. Framework for Kerberos relaying
1sudo-cve-2019-18634. Proof of Concept for CVE-2019-18634
1rocketchat-history-downloader. Download, export, and preserve Rocket.Chat user-accessible channel logs and history via the Rocket.Chat API. Designed for users who would like to preserve their conversations without having administrative access on a Rocket.Chat server.
1openvasreporting. OpenVAS Reporting: Convert OpenVAS XML report files to reports
1SharpSecDump. .Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py
1malware-agenttesla. Brief Malware Analysis of an Agent Tesla variant
1EDRs. C
1