An addition to the original Credential Guard bypass PoC, which consists in patching two global variables in wdigest.dll module loaded by LSASS.


Automatically converting mitmproxy captures to OpenAPI 3.0 specifications.


Real Intelligence Threat Analytics is a framework for detecting command and control communication through network traffic analysis.


An unhooker that will help you to remove AVs/EDRs hooks from NT API.

Simple tool called IOCTL_VOLSNAP_QUERY_NAMES_OF_SNAPSHOTS returns all snapshot, including hidden ones.

This tool automatize the DLL hijacking researches on a specified binary.


This tool uses LDAP to check a domain for known abusable Kerberos delegation settings. Currently, it supports RBCD, Constrained, Constrained w/Protocol Transition, and Unconstrained Delegation checks.

CVE-2018-25032 could potentially allow a Denial-of-Service () attack. This bug was reported by Danilo Ramos of Eideticom, Inc. It has lain in wait 13 years before being found! The « bug » was introduced in zlib, with the addition of the Z_FIXED option.

Impacket : It is now possible to add a computer account via SMB from a NTLM Relay with ntlmrelayx

Mochi is a proof-of-concept C++ loader that leverages the ChaiScript embedded scripting language to execute code. It is based on the lcscript project that extends ChaiScript with native Windows API call support. Mochi was built to allow remote loading of ChaiScript files that orchestrate lower level code and execute offensive actions with the Windows API.

An explanation of SHA-1 hashes recorded in Amcache

  Amcache registry hive


Windows System Resource Usage Monitor (SRUM)

  SRUM artifacts


