Skip to content
View leonjza's full-sized avatar
[hip, hip]
[hip, hip]

Highlights

  • Pro

Organizations

@sensepost @eveseat @bsides-vendomatic

Block or report leonjza

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

Red Team

113 repositories

Another LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory

C# 102 16 Updated Apr 18, 2022

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

C 1,294 249 Updated Nov 22, 2023

Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing programmatical access in the VBA object environmen…

Go 741 129 Updated Aug 18, 2023

MS-FSRVP coercion abuse PoC

Python 284 37 Updated Dec 30, 2021

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

C# 1,130 195 Updated Aug 27, 2023

Cobalt Strike script for ScareCrow payloads intergration (EDR/AV evasion)

Python 461 70 Updated Jul 15, 2022

A script that helps you understand why your E-Mail ended up in Spam

Python 599 86 Updated Jun 27, 2023

Shellcode injection technique. Given as C++ header, standalone Rust program or library.

Rust 695 95 Updated Sep 26, 2023

Stop Windows Defender using the Win32 API

C++ 192 43 Updated Feb 2, 2022

Create file system symbolic links from low privileged user accounts within PowerShell

C# 92 17 Updated Jun 20, 2022

Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll

C 457 54 Updated Feb 3, 2022

My collection of battle-tested Aggressor Scripts for Cobalt Strike 4.0+

PowerShell 1,065 154 Updated Apr 19, 2023

Adversary Emulation Framework

Go 8,983 1,208 Updated Feb 25, 2025

Obfuscate Go builds

Go 4,382 275 Updated Feb 22, 2025

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

C# 1,568 210 Updated Aug 6, 2022

Remote Administration Tool for Windows

C# 9,038 2,531 Updated Feb 29, 2024

A tool to generate macOS initial access vectors using Prelude Operator payloads

Python 17 2 Updated May 25, 2022

Red Team Cheatsheet in constant expansion.

1,165 164 Updated Dec 28, 2023

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs

Go 1,185 156 Updated Aug 18, 2023

Convert shellcode into ✨ different ✨ formats!

Python 348 62 Updated Jan 24, 2023

A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.

C 1,818 229 Updated Apr 7, 2024

Unchain AMSI by patching the provider’s unmonitored memory space

PowerShell 88 15 Updated Nov 24, 2022

RedGuard is a C2 front flow control tool,Can avoid Blue Teams,AVs,EDRs check.

Go 1,441 200 Updated Aug 20, 2024

Multi-Packer wrapper letting us daisy-chain various packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts watermarking, IOCs collection & PE Backdooring. You feed it wi…

PowerShell 938 135 Updated Dec 6, 2024

Create fake certs for binaries using windows binaries and the power of bat files

PowerShell 552 78 Updated Mar 28, 2024

Strelka Web UI for File Submission and Analysis

JavaScript 63 6 Updated Mar 6, 2025

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous …

HTML 7,734 1,172 Updated Feb 24, 2025