Maximilian Barz, OSEP - OSCP - CRTP
SharpKiller. Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8
351shellphishSS. Phishing Tool for Instagram, Facebook, Twitter, Snapchat, Github, Yahoo, Protonmail, Google, Spotify, Netflix, Linkedin, Wordpress, Origin, Steam, Microsoft, InstaFollowers Phisher
98CVE-2020-15906. Writeup of CVE-2020-15906
51CVE-2020-11107. This is a writeup for CVE-2020-11107 reported by Maximilian Barz
32CVE-2023-30367-mRemoteNG-password-dumper. Original PoC for CVE-2023-30367
16Auto_LFI. A simple Script which tests for LFI (Local File Inclusion) via Curl
15Suidsploit. A Tool which can exploit 137 files from GTFO-Bins automaticlly
12Silcrypt. A Simple python Ransomware
4Auto_wpscan. A little bash script to automaticlly enumerate wordpress Users and Wordpress Vulnerabillities
4Invoke-Brute7z. PowerShell Script to BruteForce 7 Zip password protected files
4airgeddon_fritzbox_et_captive_portal_plugin. A captive portal plugin to phish Fritz!Box network credentials
3SharpWinAPI. Custom C# Implementations for WinAPI Functions
3helios. An Rce Exploit through Maillog poisioning + a local file inclusion for the symfonos machine on vulnhub
3lolgolo-ng. lolbin applocker bypasses to execute ligolo-ng
3adPEAS. Powershell tool to automate Active Directory enumeration.
2PowerShell-Amsi-Hardware-Breakpoints-PoC. Amsi Hardware Break Points .Net 3.5
2awesome-injection. Centralized resource for listing and organizing known injection techniques and POCs
2csharp-rev-shell. Hacky billo implementation of a encrypted windows reverse shell in C#. Nothing special but evaded CheckPoint and Windows Defender out of the Box
2Zabbix-AutoExploiter. Zabbix 2.2 < 3.0.3 - API JSON-RPC Remote Code Execution Exploit Tool which allows to add a new SuperAdmin User via the zabbix API and theire default creds. Including a Tool to execute a low PrivShell
2Spawn-TrustedInstallerprocess. needs local admin
2Sick-Os-1.2-Remote-Root-Exploit. https://www.youtube.com/watch?v=bpbSdgK0SfE
2Cave-Finder. Tool to find code cave in PE image (x86 / x64) - Find empty space to place code in PE files
2Auto_Steg. A simple Bash program which bruteorces JPG-Files with Steghide
2EnableAllTokenPrivs. enable / disable TokenPrivilege(s)
2PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
1Instagrambot-ID-Converter. Program which converts converts Usernames to its IDs, also including an Instagrambot which automaticly follows and unfollows per Instagram IDs ..... Credits to linux_choice
1SharpExclusionFinder. C#
1CVE-2021-24884. If an authenticated user who is able to edit Wordpress PHP code in any kind, clicks a malicious link, PHP code can be edited through XSS in Formidable Forms 4.09.04.
1Deep-Live-Cam. real time face swap and one-click video deepfake with only a single image (uncensored)
1Shoggoth. Shoggoth: Asmjit Based Polymorphic Encryptor
1SecCloud.
1TangledWinExec. PoCs and tools for investigation of Windows process execution techniques
1SessionExec. Execute commands in other Sessions
1Alphabetfuscation. Convert your shellcode into an ASCII string
1GlobalUnProtect. Decrypt GlobalProtect configuration and cookie files.
1GamingServiceEoP. C++
1nmapAutomator. A script that you can run in the background!
1BootExecuteEDR. C
1DC-5-boot2root-exploit. roots after it boots :D
1CVE-2020-29254. TikiWiki 21.2 allows to edit templates without the use of a CSRF protection.
1