A curated collection of Living off the Land (LotL) attack demonstrations where trusted binaries go rogue, because if it didn’t launch calc.exe, did it even happen?
☆37Jan 7, 2026Updated 8 months ago
Alternatives and similar repositories for CalcOrItDidntHappen
Users that are interested in CalcOrItDidntHappen are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Automated script for obfuscating, rebranding and renaming the Havoc C2 Framework to evade AV/EDR and C2 hunters.☆49Aug 13, 2025Updated last year
- BeaconatorC2 is a framework for red teaming and adversarial emulation, providing a full-featured management interface, along with a catal…☆95May 25, 2026Updated 3 months ago
- Repo hacks☆21Jul 30, 2026Updated last month
- This is a GRE PoC code for Talks: From Spoofing to Tunneling: New Red Team's Networking Techniques for Initial Access and Evasion☆100Aug 23, 2025Updated last year
- Stealthy .NET assembly loading using AssemblyNative::LoadFromBuffer☆58Mar 22, 2026Updated 6 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Encode shellcode as XML-looking data. Single-header C library with a two-stage PIC loader example.☆15Feb 11, 2026Updated 7 months ago
- Helps defenders find their WSUS configurations in the wake of CVE-2025-59287☆46Oct 28, 2025Updated 10 months ago
- Orsted C2 Framework☆123Feb 9, 2026Updated 7 months ago
- PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus …☆86Jul 28, 2026Updated last month
- Coding without conditions☆15Jul 19, 2026Updated 2 months ago
- CVE-2025-68428 Proof of Concept☆24Jan 8, 2026Updated 8 months ago
- A C project that generates usernames based on input lists and format you decide yourself☆12Jun 29, 2026Updated 2 months ago
- A small How-To on creating your own weaponized WSL file☆128Jul 23, 2025Updated last year
- A cross-platform, collaborative C2 for red-teaming. Agents are cross-compilable (e.g, you can generate Windows DLLs on Linux), cross-comp…☆23Mar 7, 2025Updated last year
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- A powerful Windows command-line tool for analyzing and searching ETW (Event Tracing for Windows) provider permissions from the Windows re…☆92Jul 29, 2025Updated last year
- AutoRMM is a collection of scripts and instructions we are organizing, to test delivery mechanisms for RMM and screen sharing tools, alo…☆92Aug 3, 2025Updated last year
- POC tool to abuse windows server failover clusters☆58Aug 7, 2025Updated last year
- This project provides Base64 encoding and decoding functionality to PowerShell within Constrained Language Mode☆27Jun 25, 2024Updated 2 years ago
- Library that provides Python examples for interacting with the Cobalt Strike REST API☆25Nov 26, 2025Updated 9 months ago
- Deserialization payload generator for a variety of .NET formatters☆230Aug 25, 2026Updated 3 weeks ago
- Simple reverse ICMP shell☆15Apr 30, 2024Updated 2 years ago
- Audiodg.exe DLL hijacking for LPE with reboot-free restart primitive. Executes code as LOCAL SERVICE, escalates to SYSTEM via Scheduled T…☆127Jan 24, 2026Updated 7 months ago
- Windows Defender Manager is a tool that helps stop Windows Defender. It works with the Antimalware Service Executable of all versions of …☆44Jan 18, 2025Updated last year
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Enumerate Domain Users Without Authentication☆312Apr 22, 2025Updated last year
- ☆31Aug 13, 2025Updated last year
- Cobalt Strike notifications via NTFY.☆15Sep 24, 2024Updated last year
- ☆18Feb 29, 2024Updated 2 years ago
- Persist like a Dodder☆69May 19, 2025Updated last year
- The dragon in the dark. A red team post exploitation framework for testing security controls during red team assessments.☆508Mar 15, 2026Updated 6 months ago
- (MeetC2 a.k.a Meeting C2) - A framework abusing Google Calendar APIs.☆140Aug 17, 2026Updated last month
- a small script to collect information from a management point☆37Jan 19, 2026Updated 8 months ago
- Toolset to manipulate RPC clients by finding delayed services and masquerading as them☆113Apr 28, 2026Updated 4 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Dockerized nginx app used to create high-level timeline visuals for red team assessments☆36Feb 25, 2026Updated 6 months ago
- Remote DLL Injection with Timer-based Shellcode Execution☆215Jul 18, 2025Updated last year
- Pipeline for creating shellcode from a nostd rust project.☆27Jul 11, 2024Updated 2 years ago
- This is a Ludus range to learn and practice pivot techniques.☆19Nov 25, 2025Updated 9 months ago
- OpenShell is a lightweight, open-source reverse shell management server written in Go.☆26Mar 9, 2026Updated 6 months ago
- Slides and resources from MCTTP 2025 Talk☆70Oct 26, 2025Updated 10 months ago
- Proof-of-concept security demo illustrating how PowerShell can create trusted-looking Windows toast notifications chained together with C…☆18Apr 12, 2026Updated 5 months ago