Malicious traffic detection system
Adversary Emulation Framework
SniperPhish - The Web-Email Spear Phishing Toolkit
全新的开源漏洞测试框架,实现poc在线编辑、运行、批量测试。使用文档:
shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)
This is a project of "#Twiti: Social Listening for Threat Intelligence" (TheWebConf 2021)
Thinkphp(GUI)漏洞利用工具,支持各版本TP漏洞检测,命令执行,getshell。
Cobalt Strike Malleable C2 Design and Reference Guide
红队行动中利用白利用、免杀、自动判断网络环境生成钓鱼可执行文件。
Cobalt Strike 利用 Chrome-0day 上线
SharpSQLTools 和@Rcoil一起写的小工具,可上传下载文件,xp_cmdshell与sp_oacreate执行命令回显和clr加载程序集执行相应操作。
database of pocassist(漏洞库)
A beacon generator using Cobalt Strike and PEzor.
EarlyBird process hollowing technique (BOF) - Spawns a process in a suspended state, inject shellcode, hijack main thread with APC, and execute shellcode
Emulate and Dissect MSF and *other* attacks