An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
Chrome browser extension-based Command & Control
psexecsvc - a python implementation of PSExec's native service implementation
System Security Project
Original C Implementation of the Hell's Gate VX Technique
A Dropper POC with a focus on aiding in EDR evasion, NTDLL Unhooking followed by loading ntdll in-memory, which is present as shellcode (using pe2shc by @hasherezade). Payload encryption via System…
Script to generate malicious debian packages (debain trojans).
The recursive internet scanner for hackers. 🧡
qnx-ports / c-ares
Forked from c-ares/c-aresA C library for asynchronous DNS requests
A delicious, but malicious SSL-VPN server 🌮
Tools for controlling webcam LED on ThinkPad X230
DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely
Tool to assist during manual decompilation of Python bytecode
A tool which creates a spoofed certificate of any online website and signs an Executable for AV Evasion. Works for both Windows and Linux
Brand New Code Injection for Windows
An example of COM hijacking using a proxy DLL.
libdt is part of the "Huorong eXtendible Stream Scan Engine" project copyright by Huorong Borui (Beijing) Technology Co., Ltd.
vardyh / udis86
Forked from vmt/udis86Disassembler Library for x86 and x86-64
libcodecs is part of the "Huorong eXtendible Stream Scan Engine" project copyright by Huorong Borui (Beijing) Technology Co., Ltd.
Hello UEFI world. Simple write file using UEFI driver
PowerRunAsSystem is a PowerShell script, also available as an installable module through the PowerShell Gallery, designed to impersonate the NT AUTHORITY/SYSTEM user and execute commands or launch …
A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.
Linux eBPF backdoor over TCP. Spawn reverse shells, RCE, on prior privileged access. Less Honkin, More Tonkin.
A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29
cylance / eBPF_processor
Forked from zandi/eBPF_processorAn IDA processor for eBPF bytecode