Germany

Silky

Expert
@S1lkys

Maximilian Barz, OSEP - OSCP - CRTP

SharpKiller. Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8

351

shellphishSS. Phishing Tool for Instagram, Facebook, Twitter, Snapchat, Github, Yahoo, Protonmail, Google, Spotify, Netflix, Linkedin, Wordpress, Origin, Steam, Microsoft, InstaFollowers Phisher

98

CVE-2020-15906. Writeup of CVE-2020-15906

51

CVE-2020-11107. This is a writeup for CVE-2020-11107 reported by Maximilian Barz

32

CVE-2023-30367-mRemoteNG-password-dumper. Original PoC for CVE-2023-30367

16

Auto_LFI. A simple Script which tests for LFI (Local File Inclusion) via Curl

15

Suidsploit. A Tool which can exploit 137 files from GTFO-Bins automaticlly

12

Silcrypt. A Simple python Ransomware

4

Auto_wpscan. A little bash script to automaticlly enumerate wordpress Users and Wordpress Vulnerabillities

4

Invoke-Brute7z. PowerShell Script to BruteForce 7 Zip password protected files

4

airgeddon_fritzbox_et_captive_portal_plugin. A captive portal plugin to phish Fritz!Box network credentials

3

SharpWinAPI. Custom C# Implementations for WinAPI Functions

3

helios. An Rce Exploit through Maillog poisioning + a local file inclusion for the symfonos machine on vulnhub

3

lolgolo-ng. lolbin applocker bypasses to execute ligolo-ng

3

adPEAS. Powershell tool to automate Active Directory enumeration.

2

PowerShell-Amsi-Hardware-Breakpoints-PoC. Amsi Hardware Break Points .Net 3.5

2

awesome-injection. Centralized resource for listing and organizing known injection techniques and POCs

2

csharp-rev-shell. Hacky billo implementation of a encrypted windows reverse shell in C#. Nothing special but evaded CheckPoint and Windows Defender out of the Box

2

Zabbix-AutoExploiter. Zabbix 2.2 < 3.0.3 - API JSON-RPC Remote Code Execution Exploit Tool which allows to add a new SuperAdmin User via the zabbix API and theire default creds. Including a Tool to execute a low PrivShell

2

Spawn-TrustedInstallerprocess. needs local admin

2

Sick-Os-1.2-Remote-Root-Exploit. https://www.youtube.com/watch?v=bpbSdgK0SfE

2

Cave-Finder. Tool to find code cave in PE image (x86 / x64) - Find empty space to place code in PE files

2

Auto_Steg. A simple Bash program which bruteorces JPG-Files with Steghide

2

EnableAllTokenPrivs. enable / disable TokenPrivilege(s)

2

PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF

1

Instagrambot-ID-Converter. Program which converts converts Usernames to its IDs, also including an Instagrambot which automaticly follows and unfollows per Instagram IDs ..... Credits to linux_choice

1

SharpExclusionFinder. C#

1

CVE-2021-24884. If an authenticated user who is able to edit Wordpress PHP code in any kind, clicks a malicious link, PHP code can be edited through XSS in Formidable Forms 4.09.04.

1

Deep-Live-Cam. real time face swap and one-click video deepfake with only a single image (uncensored)

1

Shoggoth. Shoggoth: Asmjit Based Polymorphic Encryptor

1

SecCloud.

1

TangledWinExec. PoCs and tools for investigation of Windows process execution techniques

1

SessionExec. Execute commands in other Sessions

1

Alphabetfuscation. Convert your shellcode into an ASCII string

1

GlobalUnProtect. Decrypt GlobalProtect configuration and cookie files.

1

GamingServiceEoP. C++

1

nmapAutomator. A script that you can run in the background!

1

BootExecuteEDR. C

1

DC-5-boot2root-exploit. roots after it boots :D

1

CVE-2020-29254. TikiWiki 21.2 allows to edit templates without the use of a CSRF protection.

1
40
Apply