Last seen in Ring 0. Current Location Unknown

Paranoid Ninja

Elite
@paranoidninja

Brute Ratel Author | Dark Vortex Founder | Ex-Detection Engineering @CrowdStrike | Ex-Red Team/IR @Mandiant | Ex-Researcher/Threat Hunter @niiconsulting

CarbonCopy. A tool which creates a spoofed certificate of any online website and signs an Executable for AV Evasion. Works for both Windows and Linux

1.4k

Pandoras-Box. This repo contains my custom scripts for Penetration Testing and Red Team Assessments. I will keep on updating this repo as and when I get time.

359

Brute-Ratel-C4-Community-Kit. This repository contains scripts, configurations and deprecated payload loaders for Brute Ratel C4 (https://bruteratel.com/)

297

Process-Instrumentation-Syscall-Hook. A simple program to hook the current process to identify the manual syscall executions on windows

266

O365-Doppelganger. A quick handy script to harvest credentials off of a user during a Red Team and get execution of a file from the user

254

Boomerang. Boomerang is a tool to expose multiple internal servers to web/cloud. Agent & Server are pretty stable and can be used in Red Team for Multiple levels of Pivoting and exposing multiple internal services to external/other networks

226

Proxy-Function-Calls-For-ETwTI. The code is a pingback to the Dark Vortex blog: https://0xdarkvortex.dev/hiding-memory-allocations-from-mdatp-etwti-stack-tracing/

215

0xdarkvortex-MalwareDevelopment. This repo will contain code snippets for blogs: Malware on Steroids written by me at https://scriptdotsh.com/index.php/category/malware-development/

201

Proxy-DLL-Loads. The code is a pingback to the Dark Vortex blog:

190

PIC-Get-Privileges. Building and Executing Position Independent Shellcode from Object Files in Memory

174

BRC4-BOF-Artillery. C

152

Botnet-blogpost. This repo basically contains the code that was mentioned in the blogposts that was written by me at:

97

Cobaltstrike-Detection. This repo will contain the core detection, only for Cobaltstrike's leaked versions. Non-leaked version detections wont be shared

92

Brute-Ratel-External-C2-Specification. This repository provides the core to build your own External C2 Server and Connector for Brute Ratel C4

58

Threat-Hunting. This repo is dedicated to all my tricks, tweaks and modules for testing and hunting threats. This repo contains multiple directories which are in their own, different modules required for threat hunting. This repo will be updated as and when new changes are made.

57

alpha-stage-scripts. Repo contains a list of random scripts that I use while testing out random things.

48

0xdarkvortex-Reverse-Engineering. This repo contains all the code that will be referred at https://scriptdotsh.com by Paranoid Ninja

47

DotNetTracer. C code to enable ETW tracing for Dotnet Assemblies

32

Shuriken. Offensive Android Kernel on Steroids - Shuriken is an Android kernel for Oneplus 5/5T which supports multiple features for pentesting.

28

piBorg. This is a Shell Script to setup NTLM hash sniffing using the Raspberry Pi Zero. This tool can be used during Red Team assessments by attaching it to a Switch and creating a WPAD Proxy Server.

23

BRC4-Seminar-Stage-I. These are the slide decks and source code for Brute Ratel Seminar conducted on 24th August 2023. The youtube video for the seminar can be found here:

23

SheltreX. A Botnet builder built on Elasticsearch and Kibana with the help of C++ and Python3

22

0xdarkvortex-red-team-ttps-part-2. Code for blog written at 0xdarkvortex.dev Red Team TTPs Part 2

19

Chroot-Jail. This Shell script can create a chrooted environment along with a SSH Jail for the same. This can be used either for a single user jail or to create a chroot jailed group.

19

ATtiny85-RubberDucky-Sketches. This repo contains C-programmed sketches for the custom rubber ducky built using ATtiny85 microchip. Blogs on setting up the environment can be found here:

18

Exception-Junction. A full-fledged RtlVectoredExceptionHandler code written from scratch.

18

PI-Tracker. A tracker DLL which enables 'NTAPI->Syscall' tracking whenever it is loaded. It calls 'NtSetInformationProcess' API call with a callback hook and 'ProcessInstrumentationCallback' class to track all syscalls being performed via the userland.

14

FOLIAGE. Experiment on reproducing Obfuscate & Sleep

5
28
Apply