
SmuggleMyPayload
Generates HTML smuggling pages that embed and reconstruct files client-side via JavaScript, with payload encoding, chunking, obfuscation, and…

Generates HTML smuggling pages that embed and reconstruct files client-side via JavaScript, with payload encoding, chunking, obfuscation, and…

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

Threadless Process Injection using remote function hooking.

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

macOS Initial Access Payload Generator

Modern PIC implant for Windows (64 & 32 bit)

Collection of VBA macro published in our twitter / blog

ShellcodeFluctuation PoC ported to Nim

A payload delivery system which embeds payloads in an executable's icon file!

This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2…

PoC demonstrating quadratic DoS in Elixir html_sanitize_ex via crafted HTML; includes timing benchmarks, remote exploitation curl, and verification…

A simple ptrace-less shared library injector for x64 Linux

Resolves Windows APIs at runtime using vectored exception handlers and hashed lookups to hide imports and slow reverse engineering of offensive…

A new simple and powerfull packer for malware

Proof-of-concept exploit for CVE-2026-21003 demonstrating JWT authentication bypass by omitting the kid header and using the 'none' algorithm to…

Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.