Tijme Gommers's repositories
angularjs-csti-scanner
Automated client-side template injection (sandbox escape/bypass) detection for AngularJS v1.x.
not-your-average-web-crawler
A web crawler (for bug hunting) that gathers more than you can imagine.
cmstplua-uac-bypass
Cobalt Strike Beacon Object File for bypassing UAC via the CMSTPLUA COM interface.
amd-ryzen-master-driver-v17-exploit
Cobalt Strike (CS) Beacon Object File (BOF) for kernel exploitation using AMD's Ryzen Master Driver (version 17).
kernel-mii
Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551.
reverse-engineering
This repository contains some of the executables that I've cracked.
conferences
Some of the presentations, workshops, and labs I gave at public conferences.
forked-evilginx3-phishlets
This repository provides penetration testers and red teams with an extensive collection of dynamic phishing templates designed specifically for use with Evilginx3.
forked-sharphose
Asynchronous Password Spraying Tool in C# for Windows Environments
forked-donut
Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters
forked-pillow
The friendly PIL fork (Python Imaging Library)
forked-seatbelt
Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
forked-ansible-role-openvpn
Ansible Playbook for OpenVPN on CentOS/Fedora/RHEL clones
forked-best-edr-of-the-market
Little AV/EDR bypassing lab for training & learning purposes
forked-certify
Active Directory certificate abuse.
forked-dlms-cosem
A Python library for DLMS/COSEM
forked-gokrb5
Pure Go Kerberos library for clients and services
forked-jekyll-get-json
Import remote JSON data into the data for a Jekyll site
forked-kerbrute
A tool to perform Kerberos pre-auth bruteforcing
forked-kernel-callback-table-injection
Code used in this post https://captmeelo.com/redteam/maldev/2022/04/21/kernelcallbacktable-injection.html
forked-lazzy-shellcode-loader
laZzzy is a shellcode loader, developed using different open-source libraries, that demonstrates different execution techniques.
forked-lofl
Living Off the Foreign Land setup scripts
forked-pink-panther
Windows x64 handcrafted token stealing kernel-mode shellcode
forked-sprayad
A Cobalt Strike tool to audit Active Directory user accounts for weak, well known or easy guessable passwords.