Skip to content
View natesubra's full-sized avatar

Sponsoring

@mgeeky

Highlights

  • Pro

Block or report natesubra

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

Red Team

1547 repositories

A Couple of Python Scripts Leveraging MS365's GraphAPI to Send Custom Calendar Events / Emails from Cheap O365 Accounts

Python 18 5 Updated Apr 19, 2024

Find vulnerabilities in AD Group Policy, but do it better than Grouper2 did.

C# 881 73 Updated Apr 8, 2025

WMEye is a post exploitation tool that uses WMI Event Filter and MSBuild Execution for lateral movement

C# 369 59 Updated Dec 24, 2021

A windows dll injection library written in rust.

Rust 211 24 Updated Jan 12, 2026

RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, it first collects the syscall numbers of the NtOpenFile, NtC…

C++ 502 107 Updated Jan 25, 2022

Another Windows Local Privilege Escalation from Service Account to System

C 1,149 135 Updated Jan 9, 2021

It stinks

C++ 105 19 Updated Apr 22, 2022

Mimikatz implementation in pure Python

Python 3,238 415 Updated Jan 2, 2026

A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation

C# 345 48 Updated Jan 22, 2025

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

321 49 Updated Sep 23, 2022

A proof of concept for a clickjacking attack on macOS.

Swift 97 15 Updated Feb 12, 2024

Cobalt Strike beacon object file that allows you to query and make changes to the Windows Registry

C 31 8 Updated Feb 11, 2021

.net obfuscator using dnlib

C# 416 58 Updated Feb 4, 2025

Network Analysis Tool

C# 3,330 357 Updated Apr 10, 2023

.NET, PE, & Raw Shellcode Packer/Loader Written in Nim

Nim 814 131 Updated Jan 20, 2023

Artificially inflate a given binary to exceed common EDR file size limits. Can be used to bypass common EDR.

Python 125 15 Updated Apr 9, 2022

AzureRT - A Powershell module implementing various Azure Red Team tactics

PowerShell 233 31 Updated Jun 17, 2022

POC tools for exploring SMB over QUIC protocol

C 132 15 Updated Apr 6, 2022

PowerShell Obfuscation and Data Science

Jupyter Notebook 180 29 Updated May 4, 2022

MAD ATT&CK Defender: ATT&CK Adversary Emulation Repository

Python 127 28 Updated Apr 24, 2023

Post-exploit tool that enables a SOCKS tunnel via a Windows host using an extensible custom RPC proto over SMB through a named pipe.

Python 191 18 Updated Mar 4, 2021

Mochi is a proof-of-concept C++ loader that leverages the ChaiScript embedded scripting language to execute code.

C++ 101 12 Updated Mar 27, 2022

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

C# 1,628 211 Updated Aug 6, 2022

Linux eBPF backdoor over TCP. Spawn reverse shells, RCE, on prior privileged access. Less Honkin, More Tonkin.

C 1,660 183 Updated Oct 19, 2023

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

C 1,366 217 Updated Oct 27, 2023

BOF implementation of the research by @jonasLyk and the drafted PoC from @LloydLabs

C 187 23 Updated Oct 3, 2021

A way to delete a locked file, or current running executable, on disk.

C 616 100 Updated Nov 5, 2025

PowerShell SOCKS proxy with reverse proxy capabilities

PowerShell 83 12 Updated Apr 23, 2021

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

C 373 57 Updated May 24, 2022