
PINKPANTHER
Windows x64 handcrafted token stealing kernel-mode shellcode
Custom payload crafting, obfuscation, AV evasion, and delivery mechanism tools.

Windows x64 handcrafted token stealing kernel-mode shellcode

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

Collection of VBA macro published in our twitter / blog

PCI Express DIY hacking toolkit for Xilinx SP605. This repository is also home of Hyper-V Backdoor and Boot Backdoor, check readme for links and info

Autoelevate DLL search-order hijacking UAC bypass for x64 Windows 7–11, abusing 32-bit iscsicpl.exe via SysWOW64 to execute code without a UAC prompt.

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

collection of apis used in malware development


The first analysis framework for CPU microcode

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles

A small tool I made to dump the export table of PE files. The primary use case was intended for use within DLL proxying.

DEFCON 30 Mainframe buffer overlow workshop container

Cisco ASA Software and ASDM Security Research
