
h-encore
Fully chained kernel exploit for the PS Vita on firmwares 3.65-3.68
Custom payload crafting, obfuscation, AV evasion, and delivery mechanism tools.

Fully chained kernel exploit for the PS Vita on firmwares 3.65-3.68

Proof-of-concept obfuscation toolkit for C# post-exploitation tools

A BOF that runs unmanaged PEs inline

Go-based exploit development framework with built-in phases for target verification, version scanning, exploitation, and C2. Supports multiple…

InjectProc - Process Injection Techniques [This project is not maintained anymore]

HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.

poc for CVE-2024-38063 (RCE in tcpip.sys)

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Cobalt Strike UDRL for memory scanner evasion.

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

Multiplatform reverse shell generator

Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team.

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.

Toolbox containing research notes & PoC code for weaponizing .NET's DLR