A curated collection of Living off the Land (LotL) attack demonstrations where trusted binaries go rogue, because if it didn’t launch calc.exe, did it even happen?
☆37Jan 7, 2026Updated 5 months ago
Alternatives and similar repositories for CalcOrItDidntHappen
Users that are interested in CalcOrItDidntHappen are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Simple reverse ICMP shell☆14Apr 30, 2024Updated 2 years ago
- 🐧 A simple kernel-level rootkit☆21Mar 1, 2016Updated 10 years ago
- AWS X-Ray for Covert Command & Control☆50Oct 13, 2025Updated 8 months ago
- The dragon in the dark. A red team post exploitation framework for testing security controls during red team assessments.☆503Mar 15, 2026Updated 3 months ago
- This project provides Base64 encoding and decoding functionality to PowerShell within Constrained Language Mode☆27Jun 25, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- ☆24Jul 7, 2023Updated 2 years ago
- Remote process dumping automation. Use it to dump Windows credentials remotely and extract clear text with Mimikatz offline☆35Jan 3, 2020Updated 6 years ago
- C# implementation of TokenFinder. Steal M365 access tokens from Office Desktop apps☆147Feb 1, 2026Updated 5 months ago
- Searching .evtx logs for remote connections☆24Jul 6, 2023Updated 2 years ago
- Protect your servers with a secret header☆29Jun 12, 2020Updated 6 years ago
- ☆14Nov 8, 2024Updated last year
- Hundred Days of Yara Challenge☆12Jun 21, 2022Updated 4 years ago
- Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.☆64Mar 2, 2026Updated 4 months ago
- PowerShell Empire module for logging USB keystrokes via ETW☆32Nov 11, 2016Updated 9 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- POC tool to abuse windows server failover clusters☆58Aug 7, 2025Updated 10 months ago
- A PoC UDRL for Cobalt Strike built with Crystal Palace that combines Raphael Mudge's page streaming technique with a modular call gate (D…☆130Jan 21, 2026Updated 5 months ago
- Talk given at DerbyCon and RuxCon 2016☆23Sep 23, 2016Updated 9 years ago
- Minimal Indicator Storage System☆12Feb 8, 2021Updated 5 years ago
- Remote DLL Injection with Timer-based Shellcode Execution☆215Jul 18, 2025Updated 11 months ago
- A VSCode plugin to assist with BOF development.☆37Aug 14, 2024Updated last year
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆85Aug 13, 2024Updated last year
- Provides a multi-platform Graphical User Interface for hashlookup☆11Jul 12, 2024Updated last year
- AI assistant for wireshark☆93Apr 22, 2026Updated 2 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Synapse Rapid Power-up for SinkDB☆11Jun 24, 2025Updated last year
- ☆10Dec 24, 2022Updated 3 years ago
- Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.☆392Jun 20, 2026Updated 2 weeks ago
- Programmatically access a TLS certificate chain in C++ and C#☆12Oct 27, 2018Updated 7 years ago
- Havoc C2 BOF port of the KslD.sys BYOVD technique. Credential extraction from lsass via physical memory — no OpenProcess, no auditable AP…☆111Apr 22, 2026Updated 2 months ago
- regex Hunter- Fast website endpoint sensitive data and Leaks JS files endpoint API Key Scraper☆15Jun 8, 2024Updated 2 years ago
- Ivanti Connect Secure IFT TLS Stack Overflow pre-auth RCE (CVE-2025-0282)☆31Jan 18, 2025Updated last year
- Multi-agent AI system using GPT-4o, DeepSeek v3, and Llama 3.3 to detect if CVE vulnerabilities were exploited as zero-days. Analyzes…☆20Feb 13, 2026Updated 4 months ago
- A minimal IRC server☆20Jul 27, 2024Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Application Security library☆11Nov 6, 2012Updated 13 years ago
- A small go harness that uses Ollama to orchestrate LLMs in a restricted process flow☆18Sep 10, 2024Updated last year
- Decode the values of common Windows properties such as userAccountControl and sAMAccountType.☆26Apr 18, 2026Updated 2 months ago
- A Compiler from Sigma rules to VQL☆19May 18, 2026Updated last month
- ☆41May 16, 2018Updated 8 years ago
- Python script for extracting and decrypting Group Policy Preferences passwords☆26May 28, 2021Updated 5 years ago
- Helps defenders find their WSUS configurations in the wake of CVE-2025-59287☆46Oct 28, 2025Updated 8 months ago