Advanced Windows authentication token extraction and decryption tool for red team operations and security research
☆111Apr 1, 2026Updated 5 months ago
Alternatives and similar repositories for SpecterBroker
Users that are interested in SpecterBroker are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Advanced post-exploitation framework designed for Red Team operations in Entra ID, Azure and Microsoft 365 environments.☆63Apr 1, 2026Updated 5 months ago
- ☆62Feb 12, 2026Updated 7 months ago
- A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, wit…☆296Feb 21, 2026Updated 6 months ago
- open source implementation of the UDC2 spec used in Cobalt Strike☆59Jul 4, 2026Updated 2 months ago
- ☆33Mar 26, 2026Updated 5 months ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- ASPX Web Shell with COFF Loader☆136Mar 10, 2026Updated 6 months ago
- One WSL BOF to rule them all☆189Jan 14, 2026Updated 8 months ago
- .NET CLR-Stomping☆146May 20, 2026Updated 4 months ago
- psexec-like remote execution using the paexec wire protocol that supports paexec and remoteexecm2 from manageengine adselfservice plus☆44Mar 24, 2026Updated 5 months ago
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆317Aug 31, 2026Updated 2 weeks ago
- A Cobalt Strike BOF implementation of the SilentHarvest registry dumping technique☆181Apr 14, 2026Updated 5 months ago
- A Beacon Object File (BOF) for Havoc/CS to Bypass PPL and Dump Lsass☆177Sep 22, 2025Updated 11 months ago
- dcsync bof☆52Feb 13, 2026Updated 7 months ago
- Cobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from si…☆96Feb 6, 2026Updated 7 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- A collection of DPAPI hunting and parsing BOFs☆39Mar 3, 2026Updated 6 months ago
- sigreturn-oriented(SROP) based sleep obfuscation poc for Linux☆68Dec 15, 2025Updated 9 months ago
- ☆88Sep 3, 2026Updated 2 weeks ago
- A small toolkit for generating ClickOnce payloads with AppDomainManager Injection.☆18Nov 5, 2025Updated 10 months ago
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆280Apr 16, 2026Updated 5 months ago
- Lnk crafting and research tools☆185Mar 4, 2026Updated 6 months ago
- SOCKS5 proxy tool that uses Azure Storage services as a means of communication.☆364Aug 15, 2026Updated last month
- Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.☆275Dec 18, 2025Updated 9 months ago
- open source port/reimplementation of the Cobalt Strike BOF Loader as is☆73Mar 8, 2026Updated 6 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- AppLocker-Based EDR Neutralization☆343Dec 19, 2025Updated 9 months ago
- ClickForClickOnce - Generate configurable clickonce payloads☆97Apr 17, 2026Updated 5 months ago
- Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass☆146Jan 29, 2026Updated 7 months ago
- BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys.☆82Apr 11, 2026Updated 5 months ago
- Native C++ access to Active Directory over ADWS, no .NET, no WCF, no HTTP stack.☆82Mar 27, 2026Updated 5 months ago
- Memory API proxy via signed mozglue.dll☆39Jun 25, 2026Updated 2 months ago
- A Cobalt Strike RL built with Crystal Palac; module overloading, NtContinue entry transfer, call stack spoofing, sleep masking, and stati…☆256Mar 15, 2026Updated 6 months ago
- ☆193Oct 21, 2025Updated 10 months ago
- A Mythic agent for Windows written in C☆182Aug 22, 2026Updated 3 weeks ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- A flexible proxy for inspecting & transforming LDAP packets generated by any tool on the fly.☆239Updated this week
- A security research tool for enabling Chrome DevTools Protocol (CDP) debugging on Microsoft Edge browser processes at runtime.☆26Jan 2, 2026Updated 8 months ago
- Orchestrate detonating redteam artifacts in VMs with different EDRs to see their detection surface.☆89Sep 7, 2026Updated last week
- Novel Windows process injection: assembles existing open handles (process & thread), natural RWX regions, and special user APC (NtQueueAp…☆74Feb 17, 2026Updated 7 months ago
- Find jmp gadgets for call stack spoofing.☆93Oct 1, 2025Updated 11 months ago
- Beacon Object File (BOF) to obtain Entra tokens via authcode flow.☆140Jan 17, 2026Updated 8 months ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 5 months ago