Ivy is a payload creation framework that enables the execution of arbitrary VBA (macro) source code directly in memory. It achieves this by utilizing programmatical access in the VBA object environment to load, decrypt, and execute shellcode. This framework provides a powerful tool for payload creation and execution, allowing for flexible and stealthy operations. Ivy's loader is designed to load, decrypt, and execute shellcode directly in memory, making it a valuable asset for penetration testers and red teams. The framework's ability to execute arbitrary VBA source code in memory makes it an attractive option for those looking to bypass traditional security controls. With Ivy, users can create and execute custom payloads, allowing for tailored attacks and increased flexibility during operations. The framework's programmatical access to the VBA object environment also enables the execution of shellcode, making it a powerful tool in the hands of security professionals.
FEATURES
ALTERNATIVES
A C/C++ tool for remote process injection, supporting x64 and x86 operations, with system call macros generated by SysWhispers script.
CLI tool for offensive and defensive security assessments on the Joi validator library with a wide range of attacks.
Local pentest lab using docker compose to spin up victim and attacker services.
Collection of Windows oneliners for executing arbitrary code and downloading remote payloads.
A guide on basic Linux privilege escalation techniques including enumeration, data analysis, exploit customization, and trial and error.
A week-long series of articles and talks on evading Microsoft Advanced Threat Analytics (ATA) detection
A tool to remove malicious artifacts from Microsoft Office documents, preventing malware infections and data breaches.
A collection of tests for Local File Inclusion (LFI) vulnerabilities using Burp Suite.
PINNED
InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
RoboShadow
A cybersecurity platform that offers vulnerability scanning, Windows Defender and 3rd party AV management, and MFA compliance reporting, among other features.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.