Category: Exploitation

PurpleSpray

PurpleSpray: an adversary simulation tool

PurpleSpray Password spraying is an effective technique available to adversaries that allows them to gain access or escalate privileges on Windows environments. This technique can be executed in different variations...

Red Team Automation

Arsenal: Extensible Red Team Framework

Arsenal Extensible Red Team Framework Arsenal is a framework designed to be a back-end for Red Team command and control operations. It allows many Agent-C2 models to be integrated into...

TikiTorch

TikiTorch: Process Hollowing

TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process, then uses CreateRemoteThread to run the desired shellcode within that target process....

Sharp-Suite

Sharp-Suite: Penetration Testing tools in C#

Sharp-Suite SwampThing SwampThing lets you spoof process command line args (x32/64). Essentially you create a process in a suspended state, rewrite the PEB, resume and finally revert the PEB. The...

PowerShell Empire Dashboarding

BlueCommand: Dashboarding and Tooling front-end for PowerShell Empire

BlueCommand BlueCommand is a dashboard and tooling front-end for PowerShell Empire using PowerShell Universal Dashboard from Adam Driscoll. WARNING: This project does not nearly scratch the surface of interacting with all the capabilities of PowerShell Empire....

chkdfront 

chkdfront: Check Domain Fronting

Check Domain Fronting (chkdfront) chkdfront checks if your domain fronting is working by testing the targeted domain (fronted domain) against your domain front domain. Features Checking your domain fronted against...