-
NSA
- Fort Meade, Maryland
Highlights
- Pro
red_team_tools
A BOF to enumerate system process, their protection levels, and more.
An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution
Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a sacrificial Process as target process + (ACG+Bloc…
A version of NetLoader, Execute Assemblies and Bypass ETW and AMSI using Hardware Breakpoints
Make everyone in your VLAN ASRep roastable
Just another Powerview alternative but on steroids
Collection of Beacon Object Files (BOF) for Cobalt Strike
TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts
A Python script for creating `.lnk` (shortcut) files with embedded encoded data and packaging them into ZIP archives.
Two new offensive techniques using Windows Fibers: PoisonFiber (The first remote enumeration & Fiber injection capability POC tool) PhantomThread (An evolved callstack-masking implementation)
Evasive shellcode loader for bypassing event-based injection detection (PoC)
Use the Netlogon Remote Protocol (MS-NRPC) to dump the target hash.
SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS, ICMP, HTTP Encapsulation, HTTP/Socks Proxies, UDP...)
Enumerate information from NTLM authentication enabled web endpoints 🔎
Python tool to Check running WebClient services on multiple targets based on @leechristensen
BrowserSnatch is a powerful browser stealer or browser data extraction tool intended to be used for ethical hacking or penetration testing.
🧠 The ultimate, community-curated resource for Beacon Object Files (BOFs) — tutorials, how-tos, deep dives, and reference materials.
Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data
Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes
SOCKS5 proxy tool that uses Azure Blob Storage as a means of communication.