Just a blog to preserve some thoughts about Red Teaming :)

Chankro

Description
        Bypass disable_functions and open_basedir via putenv() and mail().
Author
        @TheXC3LL
Download
        https://github.com/TarlogicSecurity/Chankro

Mssqlproxy

Description
        Toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse.
Author
        @xassiz & @TheXC3LL
Download
        https://github.com/blackarrowsec/mssqlproxy

Arecibo

Description
        Endpoint for Out-of-Band Exfiltration (DNS & HTTP).
Author
        @TheXC3LL & @xassiz
Download
        https://github.com/TarlogicSecurity/Arecibo

F-Isolation

Description
        Small script to transfer files between a VDI and host using OCR & Keyboard emulation.
Author
        @lowSoA & @TheXC3LL
Download
        https://gist.github.com/X-C3LL/20a5af5c692dbaae551e32fcf99d25f2