RedTeam fork robot. ⚠️Please check the source code carefully before using the tool. :)
CVE-2023-21839. Weblogic CVE-2023-21839 RCE (无需Java依赖一键RCE)
115FilelessRemotePE. Loading Fileless Remote PE from URI to memory with argument passing and ETW patching and NTDLL unhooking and No New Thread technique
75CobaltPatch. Cobalt Strike Malleable Profile Inline Patch Template: A Position Independent Code (PIC) Code Template For Creating Shellcode That Can Be Appended In Stage / Post-Ex Blocks. Made for C Programmers
43MSBuild-AL-Bypass. C# shellcode runner adapted to run from a csproj to be triggered by MSBuild
26CVE-2018-19320. Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)
19AB. Cs-Sleep-Mask-Fiber
18ImpulsiveDLLHijack. C# based tool which automates the process of discovering and exploiting DLL Hijacks in target binaries. The Hijacked paths discovered can later be weaponized during Red Team Operations to evade EDR's.
17Fenrir. stack spoofing
15CVE-2022-21894-Payload. Example payload for CVE-2022-21894
15Artillery. CIA UAC bypass implementation that utilizes elevated COM object to write to System32 and an auto-elevated process to execute as administrator.
14DecryptTeamViewer. Enumerate and decrypt TeamViewer settings from registry
10ekko-rs. Rusty Ekko - Sleep Obfuscation in Rust
9Zipper. Zipper, a CobaltStrike file and folder compression utility.
8RustSCRunner. Shellcode Runner/Injector in Rust using NTDLL functions directly with the ntapi Library
8LocklessBof. Lockless BOF
8ElusiveMice. Cobalt Strike User-Defined Reflective Loader with AV/EDR Evasion in mind
8ColorDataProxyUACBypass. Exploits undocumented elevated COM interface ICMLuaUtil via process spoofing to edit registry then calls ColorDataProxy to trigger UAC bypass. Win 7 & up.
6UAC-BOF-Bonanza. Collection of UAC Bypass Techniques Weaponized as BOFs
6Loki. 🧙♂️ Node JS C2 for backdooring vulnerable Electron applications
6PrintSpoofer. Abusing Impersonation Privileges on Windows 10 and Server 2019
6shellcode-template. A cmkr based win32 shellcode template for a unified build platform and more production friendly structure/testing.
6DllNotificationInjection. A POC of a new “threadless” process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote processes.
6LdrLibraryEx. A small x64 library to load dll's into memory.
5S4UTomato. Escalate Service Account To LocalSystem via Kerberos
5FlavorTown. Various ways to execute shellcode
5LoudSunRun. My shitty attempt at tampering with the callstack based on the work of namazso, SilentMoonWalk, and VulcanRaven
5EtwPatching. Patching Event Tracing for Windows, by overwriting "call ntdll!EtwpEventWriteFull" inside ntdll!EtwEventWrite , the patched call do the actual Event Writing
4HidePort. Hide Port In Windows
4fileSearcher. A simple BOF (Beacon Object File) to search files in the system
4BrowserSnatch. This project steals important data from all chromium and gecko browsers installed in the system and gather the data in a stealer db to be exfiltrated out.
4CVE-2022-25636. CVE-2022-25636
4ClamAV_0Day_exploit. ClamAV_0Day_exploit
4Cookie-Graber-BOF. C or BOF file to extract WebKit master key to decrypt user cookie
4Spawn_bof. Bof Spawn process using NtCreateUserProcess with capabilities like ppid spoofing and block dll policy.
4PR0CESS. some gadgets about windows process and ready to use :)
4DeadPotato. DeadPotato is a windows privilege escalation utility from the Potato family of exploits, leveraging the SeImpersonate right to obtain SYSTEM privileges. This script has been customized from the original GodPotato source code by BeichenDream.
3CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability. Microsoft-Outlook-Remote-Code-Execution-Vulnerability
3arch_enum. A small tool for rapid enumeration of CPUID, and MSR fields.
3HiddenDesktop. HVNC for Cobalt Strike
3Terminator. Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes
3bypass_uac_bof. 一个普通的BOF用来BypassUAC
3DocPlz. Documents Exfiltration project for fun and educational purposes
3SignatureGate. Weaponized HellsGate/SigFlip
3GhostMapperUM. manual map unsigned driver over signed memory
3HWSyscalls. HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.
3CoercedPotato. C
3DojoLoader. Generic PE loader for fast prototyping evasion techniques
3OutLook. 一款OutLook信息收集工具
3ImmoralFiber. C++
3bof-exec. Tool That Loads and Executes a Beacon Object File With Arguments
3Rust-for-Malware-Development. This repository contains my complete resources and coding practices for malware development using Rust 🦀.
3xor_cpp_shellode. CPP XOR and execute shellcode
1hybris. Tool to spawn processes as SYSTEM by stealing tokens
1WPS-CVE-2022-24934. Fake WPS Update Server PoC
1Domain-Recon-BOF. This is a BOF to return Domain Forest Name, Domain Name, Domain Controller+address+sitename
12022-LPE-UAF. CVE-2022-2588
1