All I know is that I know nothing. I like Windows, Active Directory and IoT/Hardware hacking.
PetitPotam. PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.
2.3kSharpWeb. .NET 2.0 CLR project to retrieve saved browser credentials from Google Chrome, Mozilla Firefox and Microsoft Internet Explorer/Edge.
22Elevator. UAC Bypass by abusing RPC and debug objects.
7CheckPlease. Payload-Agnostic Implant Security
6LaMarre. Topotam random stuff repos
6BOF_dumpclip. Beacon Object Files to dump content of clipboard
6Backstab. A tool to kill antimalware protected processes
6C2-Tool-Collection. A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.
5EnumStrike. Cobalt Strike Aggressor script to automate host and domain enumeration.
4Invoke-Phant0m. PowerShell
4Group3r. Coming Soon!
2ZipExec. A unique technique to execute binaries from a password protected zip
2Infosec_Reference. An Information Security Reference That Doesn't Suck
2palinka_c2. Just another useless C2 occupying space in some HDD somewhere.
2SysWhisper3. SysWhispers on Steroids - AV/EDR evasion via direct system calls.
2CobaltBus. Cobalt Strike External C2 Integration With Azure Servicebus, C2 traffic via Azure Servicebus
2Injector. Complete Arsenal of Memory injection and other techniques for red-teaming in Windows
2Certipy. Tool for Active Directory Certificate Services enumeration and abuse
2SigFlip. SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.
2ADCSPwn. A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service.
2CheeseOunce. Coerce Windows machines auth via MS-EVEN
2Posh-SecMod. PowerShell Module with Security cmdlets for security work
2EDRSandblast. C
2adalanche. Active Directory ACL Visualizer and Explorer - who's really Domain Admin?
2PrintSpoofer. Abusing Impersonation Privileges on Windows 10 and Server 2019
1Injectors. 💉 DLL/Shellcode injection techniques
1Athena. C#
1TokenStomp. C# implementation of the token privilege removal flaw discovered by @GabrielLandau/Elastic
1Azure-Red-Team. Azure Security Resources and Notes
1DFSCoerce. Python
1AzureAD-Attack-Defense. This publication is a collection of various common attack scenarios on Azure Active Directory and how they can be mitigated or detected.
1BofAllTheThings. Creating a repository with all public Beacon Object Files (BoFs)
1EfsPotato. Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability).
1Revenant. Revenant - A 3rd party agent for Havoc that aim to demonstrate evasion techniques in the context of a C2 framework
1LdapRelayScan. Check for LDAP protections regarding the relay of NTLM authentication
1githubC2. Abusing Github API to host our C2 traffic, usefull for bypassing blocking firewall rules if github is in the target white list , and in case you don't have C2 infrastructure , now you have a free one
1routersploit. Exploitation Framework for Embedded Devices
1lsarelayx. NTLM relaying for Windows made easy
1BOF-RegSave. Dumping SAM / SECURITY / SYSTEM registry hives with a Beacon Object File
1FOLIAGE. Experiment on reproducing Obfuscate & Sleep
1PowerDropper. App that generates PowerShell dropper scripts for .NET executables
1DNSStager. Hide your payload in DNS
1