Qatar

Usman Sikander

Expert
@Offensive-Panda

An infosec guy who's constantly seeking for knowledge.

ShadowDumper. Shadow Dumper is a powerful tool used to dump LSASS memory, often needed in penetration testing and red teaming. It uses multiple advanced techniques to dump memory, allowing to access sensitive data in LSASS memory.

586

ProcessInjectionTechniques. This comprehensive process injection series is crafted for cybersecurity enthusiasts, researchers, and professionals who aim to stay at the forefront of the field. It serves as a central repository of knowledge, offering in-depth exploration of various process injection techniques and methods used by adversaries.

459

RWX_MEMEORY_HUNT_AND_INJECTION_DV. Abusing Windows fork API and OneDrive.exe process to inject the malicious shellcode without allocating new RWX memory region.

292

LsassReflectDumping. This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created, it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process

219

DefenseEvasionTechniques. This comprehensive and central repository is designed for cybersecurity enthusiasts, researchers, and professionals seeking to stay ahead in the field. It provides a valuable resource for those dedicated to improving their skills in malware development, malware research, offensive security, security defenses and measures.

159

.NET_PROFILER_DLL_LOADING. .NET profiler DLL loading can be abused to make a legit .NET application load a malicious DLL using environment variables. This exploit is loading a malicious DLL using Task Scheduler (MMC) to bypass UAC and getting admin privileges.

50

DV_NEW. This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)

50

C2_Elevated_Shell_DLL_Hijcking. DLL Hijacking and Mock directories technique to bypass Windows UAC security feature and getting high-level privileged reverse shell. Security researchers identified this technique which uses a simplified process of DLL hijacking and mock folders to bypass UAC control. I tested this on Windows 10,11 and bypassed Windows 10 UAC security feature.

43

NT-AUTHORITY-SYSTEM-CONTEXT-RTCORE. This exploit rebuilds and exploit the CVE-2019-16098 which is in driver Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, I/O ports, and MSRs. Instead of hardcoded base address of Ntoskrnl.exe, I calculated it dynamically and recalulated the fields offsets

34

D3MPSEC. "D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system calls, randomized procedures, and prototype name obfuscation. Its primary purpose is to bypass both static and dynamic analysis techniques commonly employed by security measures.

29

PEB_WALK_AND_API_OBFUSCATION_INJECTION. This exploit use PEB walk technique to resolve API calls dynamically, obfuscate all API calls to perform process injection.

28

MalwareAnalysis. This central repository is crafted for cybersecurity enthusiasts, researchers, and professionals aiming to advance their skills. It offers valuable resources for those focused on analyzing and understanding different types of malware.

23

WPM-MAJIC-ENTRY-POINT-INJECTION. This exploit is utilising AddressOfEntryPoint of process which is RX and using WriteProcessMemory internal magic to change the permission and write the shellcode.

20

on-disk-detection-bypass. Direct syscalls Injection to bypass AV/EDR

10

Persistence_AND_Anti_Sandbox. This repository contains the c# code which is using latest persistence technique and multiple anti-vm, anti-sandboxes techniques. Creating persistence by using WindowsApps folder, schtasks, powershell cmdlet (Get-Variable).

9

Bypass-and-Defeat-Defender. Powerfull scripts to bypass windows defender

8

Offensive-Panda.github.io. Welcome to my professional portfolio, a centralized hub where you can access a comprehensive collection of my cybersecurity series, blogs and projects, expertly organized for your exploration and insight.

5

NT-AUTHORITY-Shell. Simple batch scripts to get NT-Authority

5

Collect_Threat_Intel_AND_Malware_Using_Honeypots. This code run as a service continuous monitoring all Sysmon event logs and take action based on events generated by attackers activities. Also sending filtered and contextual details on telegram bots to update administrators. Uploading and capturing all malware's dropped by attackers.

5

Chrome-Password-Stealer. I have created a python based exploit which is getting Username, Passwords, Url's from Google Chrome

5

BadPowerShell. This repository includes the powershell scripts. One script is used to convert any EXE file into hexadecimal format and other script can execute converted hex. Converted hex will upload on server and you can get hex, create EXE and execute it. This technique will help to bypass network level security controls.

3

Telegram-Bot-RAT. Send victim Information using telegram bot. Simple php script to connect with telegram bot and sent user agent information on telegram.

3

SHELLCODE_FORMATS_COVERTOR. This scirpt will convert you binary form (raw shellcode) into C, C# and base64 encoded form.

3

Web_Request_AND_Anti-Sandbox. This reposiorty contains the c# code which is using latest persistence technique and multiple anti-vm, anti-sandboxes techniques. In this program, I am using 4 anti-vm and anti-sanboxe techniques

2

AdvPhishing. This is Advance Phishing Tool ! OTP PHISHING

2

Reverse_Shell_Over_TCp. I have created a reverse connection client from scratch in the C# programming language and execute arbitrary commands to perform C&C on the target system. To connect to the host with port, you need to pass the IP address in the first parameter and integer port number as the second argument.

2

Exfiltration. Data-Exfiltration using FTP service

2

pyransom. Ransomware script based on AES-CBC (Fernet Token) and RSA (PKCS1-OAEP) cryptosystem.

1

offsec-tools. Compiled tools for internal assessments

1

VirtualBoxSystemInformationModify. Modify Virtual Box System Information

1

2FAInstagram. Bypass 2FA Instagram

1

PE-MalDoc. Privileges Escalation using VBA macro. You can use this script in office document to escalate windows privileges using registry changing.

1

exploits. Miscellaneous exploit code

1

DLLirant. DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

1

MalDoc-VBA. VBA script to download anything from internet

1

Conti-Ransomware. Full source of the Conti Ransomware Including the missing Locker files from the original leak. I have fixed some of the errors intentionally introduced by the leaker to prevent the locker from being built. The Queue header file which implements a few linked list data structures that Conti uses for task scheduling in the Threadpool had several missi

1

C2-Tool-Collection. A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

1

fakelogonscreen. Fake Windows logon screen to steal passwords

1

MimikatzFUD. PowerShell

1

Offensive-Panda.

1
40
Apply