aus-mate's starred repositories

linux-kernel-exploitation

A collection of links related to Linux kernel security and exploitation

Language:C#License:Apache-2.0Stargazers:1358Issues:41Issues:1

C2-Tool-Collection

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

ProtectMyTooling

Multi-Packer wrapper letting us daisy-chain various packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts watermarking, IOCs collection & PE Backdooring. You feed it with your implant, it does a lot of sneaky things and spits out obfuscated executable.

Language:PowerShellLicense:MITStargazers:840Issues:26Issues:5

KrbRelay

Framework for Kerberos relaying

DripLoader

Evasive shellcode loader for bypassing event-based injection detection (PoC)

Language:C++License:MITStargazers:695Issues:15Issues:2

StandIn

StandIn is a small .NET35/45 AD post-exploitation toolkit

BOF.NET

A .NET Runtime for Cobalt Strike's Beacon Object Files

Stracciatella

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

Language:C#License:GPL-3.0Stargazers:494Issues:14Issues:9

rootkit-rs

Rusty Rootkit - Windows Kernel Rookit in Rust (Codename: Eagle)

Language:RustLicense:MITStargazers:487Issues:15Issues:0

ScareCrow-CobaltStrike

Cobalt Strike script for ScareCrow payloads intergration (EDR/AV evasion)

Language:PythonLicense:MITStargazers:453Issues:9Issues:8

RecycledGate

Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll

Language:CStargazers:434Issues:11Issues:0

GoMapEnum

User enumeration and password bruteforce on Azure, ADFS, OWA, O365, Teams and gather emails on Linkedin

Language:GoLicense:GPL-3.0Stargazers:416Issues:14Issues:7

BofAllTheThings

Creating a repository with all public Beacon Object Files (BoFs)

VulnCases

Vulnerability examples.

Language:C++License:BSD-3-ClauseStargazers:399Issues:20Issues:0

SharpImpersonation

A User Impersonation tool - via Token or Shellcode injection

Language:C#License:BSD-3-ClauseStargazers:397Issues:13Issues:4

NTLMRelay2Self

An other No-Fix LPE, NTLMRelay2Self over HTTP (Webdav).

XLL_Phishing

XLL Phishing Tradecraft

Language:CLicense:MITStargazers:386Issues:8Issues:0

SharpEventPersist

Persistence by writing/reading shellcode from Event Log

DeepSleep

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

SharpShares

Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain

Language:C#License:MITStargazers:313Issues:11Issues:3

AsStrongAsFuck

A console obfuscator for .NET assemblies.

Language:C#License:MITStargazers:304Issues:15Issues:6

COM-Hunter

COM Hijacking VOODOO

Language:C#License:MITStargazers:249Issues:2Issues:2

PersistAssist

Fully modular persistence framework

Language:C#Stargazers:248Issues:6Issues:0

Shellcode-Loader

Open repository for learning dynamic shellcode loading (sample in many programming languages)

Language:C++Stargazers:207Issues:9Issues:0
Language:PythonStargazers:178Issues:1Issues:0

ObjCShellcodeLoader

macOS shellcode loader written in Objective-C

Language:Objective-CStargazers:48Issues:3Issues:1

archives

Here is my arsenals