CoffeeLdr
CoffeeLdr is a BOF loader. This project can be used for testing Beacon Object files without using the Cobalt Strike framework or can be used to give custom implants a way to execute BOFs that where designed for Cobalt strike. Most of the Beacon Api (fork&run and injection) functions are empty for custom implementations.
RDPHijack
Cobalt Strike BOF that uses
WinStationConnect
API to perform local / remote RDP session hijacking.
sccmdecryptpoc.cs
SCCM Account Password Decryption PoC by Adam Chester.
Converting a simple malware dropper written in C to x64 assembly
https://www.accidentalrebel.com/converting-a-malware-dropper-to-x64-assembly.html
Dump Citrix Secure Access auth cookie from the process memory
https://github.com/soufianetahiri/CitrixSecureAccessAuthCookieDump
NetstatWithTimestamps - netstat like with timestamps for connections.
https://github.com/gtworek/PSBits/tree/master/NetstatWithTimestamps
OneDriveExplorer
Command line and GUI based application for reconstructing the folder structure of OneDrive
DFSCoerce
PoC for MS-DFSNM coerce NTLM authentication using NetrDfsRemoveStdRoot method
CVE-2022-23222 PoC
Linux Kernel eBPF Local Privilege Escalation
⚠️ For educational/research purposes only. Use at your own risk.
usbsas
A free and open source (GPLv3) tool and framework for securely reading untrusted USB mass storage devices.
Ica2Tcp
Ica2Tcp is a tool developed in C allowing to proxy any TCP connection inside a Citrix ICA connection.
An addition to the original Credential Guard bypass PoC, which consists in patching two global variables in wdigest.dll
module loaded by LSASS.
https://github.com/itm4n/Pentest-Windows/tree/main/CredGuardBypassOffsets
A simple PoC for creating false AppLocker hash cache entry for a file.
https://github.com/gtworek/PSBits/blob/master/CopyEAs/SetAppLockerHashCache.c
C++ implementation of the Perun's Fart Evasion technique
mitmproxy2swagger
Automatically converting mitmproxy captures to OpenAPI 3.0 specifications.
RITA
Real Intelligence Threat Analytics is a framework for detecting command and control communication through network traffic analysis.
LiveCloudKd & MemProcFs fixes for Windows 11 and WinDBG 10.0.22000
KernelCallbackTable-Injection
HalosUnhooker
An unhooker that will help you to remove AVs/EDRs hooks from NT API.
247365