Framework for Man-In-The-Middle attacks
Repositories
byt3bl33d3r repositories
Optional plugins for MITMf
Modern problems require modern solutions
A C# stager for SILENTTRINITY (https://github.com/byt3bl33d3r/SILENTTRINITY)
DLL sideloading/proxying with Nim!
Toolbox containing research notes & PoC code for weaponizing .NET's DLR
My experiments in weaponizing Nim (https://nim-lang.org/)
Simple (relatively) things allowing you to dig a bit deeper than usual.
Powershell-based bot framework
PowerSploit - A PowerShell Post-Exploitation Framework
Exchange your privileges for Domain Admin privs by abusing Exchange
Automate creating resilient, disposable, secure and agile infrastructure for Red Teams
An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR
Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
Slides from various talks that I've given over the years
Spoof emails from any of the +2 Million domains using MailChannels (DEFCON 31 Talk)
Scripts to make password spraying attacks against Lync/S4B, OWA & O365 a lot quicker, less painful and more efficient
A script that can see if an email address is valid in Office365 (user/email enumeration). This does not perform any login attempts, is unthrottled, and is incredibly useful for social engineering assessments to find which emails exist and which don't.
An async Python client library for Empire's RESTful API
Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to make life easier.