Composite Moniker Proof of Concept exploit for CVE-2017-8570.
https://github.com/rxwx/CVE-2017-8570
Exploit toolkit CVE-2017-8759 is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft .NET Framework RCE.
https://github.com/bhdresh/CVE-2017-8759
CVE-2017-11882 Exploit accepts over 17k bytes long command/code in maximum.
https://github.com/unamer/CVE-2017-11882
Adobe Flash Exploit CVE-2018-4878.
https://github.com/anbai-inc/CVE-2018-4878
Exploit toolkit CVE-2017-0199 is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft Office RCE.
https://github.com/bhdresh/CVE-2017-0199
demiguise is a HTA encryption tool for RedTeams.
https://github.com/nccgroup/demiguise
Office-DDE-Payloads collection of scripts and templates to generate Office documents embedded with the DDE, macro-less command execution technique.
https://github.com/0xdeadbeefJERKY/Office-DDE-Payloads
CACTUSTORCH Payload Generation for Adversary Simulations.
https://github.com/mdsecactivebreach/CACTUSTORCH
SharpShooter is a payload creation framework for the retrieval and execution of arbitrary CSharp source code.
https://github.com/mdsecactivebreach/SharpShooter
Don't kill my cat is a tool that generates obfuscated shellcode that is stored inside of polyglot images. The image is 100% valid and also 100% valid shellcode.
https://github.com/Mr-Un1k0d3r/DKMC
Malicious Macro Generator Utility Simple utility design to generate obfuscated macro that also include a AV / Sandboxes escape mechanism.
https://github.com/Mr-Un1k0d3r/MaliciousMacroGenerator
SCT Obfuscator Cobalt Strike SCT payload obfuscator.
https://github.com/Mr-Un1k0d3r/SCT-obfuscator
Invoke-Obfuscation PowerShell Obfuscator.
https://github.com/danielbohannon/Invoke-Obfuscation
Invoke-DOSfuscation cmd.exe Command Obfuscation Generator & Detection Test Harness.
https://github.com/danielbohannon/Invoke-DOSfuscation
morphHTA Morphing Cobalt Strike's evil.HTA.
https://github.com/vysec/morphHTA
Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory.
https://github.com/trustedsec/unicorn
Shellter is a dynamic shellcode injection tool, and the first truly dynamic PE infector ever created.
https://www.shellterproject.com/
EmbedInHTML Embed and hide any file in an HTML file.
https://github.com/Arno0x/EmbedInHTML
SigThief Stealing Signatures and Making One Invalid Signature at a Time.
https://github.com/secretsquirrel/SigThief
Veil is a tool designed to generate metasploit payloads that bypass common anti-virus solutions.
https://github.com/Veil-Framework/Veil
CheckPlease Sandbox evasion modules written in PowerShell, Python, Go, Ruby, C, C#, Perl, and Rust.
https://github.com/Arvanaghi/CheckPlease
Invoke-PSImage is a tool to embeded a PowerShell script in the pixels of a PNG file and generates a oneliner to execute.
https://github.com/peewpw/Invoke-PSImage
LuckyStrike a PowerShell based utility for the creation of malicious Office macro documents. To be used for pentesting or educational purposes only.
https://github.com/curi0usJack/luckystrike
ClickOnceGenerator Quick Malicious ClickOnceGenerator for Red Team. The default application a simple WebBrowser widget that point to a website of your choice.
https://github.com/Mr-Un1k0d3r/ClickOnceGenerator
macropack is a tool by
@EmericNasi used to automatize obfuscation and generation of MS Office documents, VB scripts, and other formats for pentest, demo, and social engineering assessments.
https://github.com/sevagas/macropack
StarFighters a JavaScript and VBScript Based Empire Launcher.
https://github.com/Cn33liz/StarFighters
npspayload this script will generate payloads for basic intrusion detection avoidance. It utilizes publicly demonstrated techniques from several different sources.
https://github.com/trustedsec/npspayload