Crystal port of GodPotato to abuse SeImpersonatePrivilege with indirect syscalls, dynamic API resolution and compile-time string obfuscation. Run commands, reverse shells or add users
-
Updated
Aug 22, 2026 - Crystal
Crystal port of GodPotato to abuse SeImpersonatePrivilege with indirect syscalls, dynamic API resolution and compile-time string obfuscation. Run commands, reverse shells or add users
The only OSCP preparation repository you need: notes, tooling, reporting, prep-list, methodology, and security resources.
kb=$(cat sillynotes.txt)
This repo has a collection of scripts and exploits for OSCP-style labs. It covers enumeration, exploitation, web testing, and reverse shells.
netcat-like CLI tool with advanced features for bind/reverse shells
Bypassing Event Tracing for Windows (ETW) with CSharp
Guide for OSCP preparation!
Auto-chaining ROP exploit builder for x86-64 ELF (Rust)
Modular, cross-platform Chromium profile database file stealer focused on EDR/AV evasion
Invoke-CredHunt: Uncover Hidden Credentials and Passwords
🔥 NetPhantom - Network Phantom Poisoning Authentication Capture Tool
Updated Python 3 code for Black Hat Python 2nd Edition — tested, fixed, and modernized
Web Exploit Server (WES) - a self-hosted exploit server for web application penetration testing. Stores arbitrary HTTP responses, serves them from a host you control, and logs every request that comes back.
🔍 Exploit CVE-2024-0670 in CheckMK agents for local privilege escalation using a robust C++ tool designed for security professionals.
Add a description, image, and links to the offsensive-security topic page so that developers can more easily learn about it.
To associate your repository with the offsensive-security topic, visit your repo's landing page and select "manage topics."