Stars
Quickly and easily dump Sticky Notes content on Windows 10
early cascade injection PoC based on Outflanks blog post, in rust
A caddy module for IP geofencing your caddy web server using ipbase.com
Pentesting cheatsheet with all the commands I learned during my learning journey. Will try to to keep it up-to-date.
real time face swap and one-click video deepfake with only a single image
SHELLSILO is a cutting-edge tool that translates C syntax into syscall assembly and its corresponding shellcode. It streamlines the process of constructing and utilizing structures, assigning varia…
Chrome-extension implant that turns victim Chrome browsers into fully-functional HTTP proxies, allowing you to browse sites as your victims.
Respotter is a Responder honeypot. Detect Responder in your environment as soon as it's spun up.
Hide from the InstanceCredentialExfiltration GuardDuty finding by using VPC Endpoints
A powerful browser extension to create, edit and delete cookies
BOF to steal browser cookies & credentials
Interact with Chromium-based browsers' debug port to view open tabs, installed extensions, and cookies
Threadless Process Injection through entry point hijacking
Fetch all the URLs that the Wayback Machine knows about for a domain
Everything and anything related to password spraying
gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...
Youtube as C2 channel - Control Windows systems uploading QR videos to Youtube
DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.
A memory-based evasion technique which makes shellcode invisible from process start to end.
A slightly more fun way to disable windows defender + firewall. (through the WSC api)
Command line tool for dumping Jenkins credentials.
Frida scripts to directly MitM all HTTPS traffic from a target mobile application