tothi's starred repositories

Language:CLicense:AGPL-3.0Stargazers:9696Issues:385Issues:760

Havoc

The Havoc Framework

Language:GoLicense:GPL-3.0Stargazers:6806Issues:101Issues:338

PlayIntegrityFix

Fix Play Integrity (and SafetyNet) verdicts.

Language:C++License:GPL-3.0Stargazers:5073Issues:76Issues:303

ATC_MiThermometer

Custom firmware for the Xiaomi Thermometers and Telink Flasher

Language:CLicense:NOASSERTIONStargazers:2945Issues:83Issues:478

hayabusa

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

Language:RustLicense:AGPL-3.0Stargazers:2282Issues:41Issues:644

ROADtools

A collection of Azure AD/Entra tools for offensive and defensive security purposes

Language:PythonLicense:MITStargazers:1887Issues:44Issues:59

PlayIntegrityFork

Fix Play Integrity (and SafetyNet) verdicts, allowing custom fields and props

Language:C++License:GPL-3.0Stargazers:1079Issues:31Issues:0

ChromeKatz

Dump cookies and credentials directly from Chrome/Edge process memory

Language:C++License:BSD-3-ClauseStargazers:1032Issues:12Issues:12

steganography

Simple C++ Image Steganography tool to encrypt and hide files insde images using Least-Significant-Bit encoding.

Language:C++License:MITStargazers:996Issues:8Issues:4

samloader

Download Samsung firmware from official servers

Language:PythonLicense:GPL-3.0Stargazers:813Issues:26Issues:0

NetLoader

Loads any C# binary in mem, patching AMSI + ETW.

Pyramid

a tool to help operate in EDRs' blind spots

Language:PythonLicense:Apache-2.0Stargazers:651Issues:12Issues:10

CVE-2024-38063

poc for CVE-2024-38063 (RCE in tcpip.sys)

Language:PythonLicense:MITStargazers:615Issues:4Issues:6

TokenTactics

Azure JWT Token Manipulation Toolset

Language:PowerShellLicense:BSD-3-ClauseStargazers:599Issues:14Issues:5

Rucky

A simple to use USB HID Rubber Ducky Launch Pad for Android.

Language:JavaLicense:GPL-3.0Stargazers:540Issues:34Issues:63

DavRelayUp

DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced (the default settings).

EVTX-to-MITRE-Attack

Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.

EDR-Preloader

An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer

C2_RedTeam_CheatSheets

Useful C2 techniques and cheatsheets learned from engagements

BackupOperatorToDA

From an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain Controller

PowershellKerberos

Some scripts to abuse kerberos using Powershell

cookie-monster

BOF to steal browser cookies & credentials

Language:CLicense:GPL-3.0Stargazers:219Issues:5Issues:7

KeyTabExtract

Extracts Key Values from .keytab files

Language:PythonStargazers:213Issues:2Issues:0

TokenTacticsV2

A fork of the great TokenTactics with support for CAE and token endpoint v2

Language:PowerShellLicense:BSD-3-ClauseStargazers:194Issues:4Issues:0

ariston-remotethermo-home-assistant-v3

Ariston NET remotethermo integration for Home Assistant based on API

Language:PythonLicense:MITStargazers:161Issues:18Issues:177

vscode-compare-folders

The source code of the extension CompareFolders

Language:TypeScriptLicense:MITStargazers:115Issues:3Issues:99

deviceCode2WinHello

A small script that automates Entra ID persistence with Windows Hello For Business key

Language:PythonLicense:MITStargazers:47Issues:3Issues:1

officedump

Dump document encryption password from Office process memory

chunk-nordic

Yet another TCP-over-HTTP(S) tunnel

Language:PythonLicense:MITStargazers:24Issues:4Issues:5