
Pokemon-Shellcode-Loader
Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

Threadless Process Injection using remote function hooking.

macOS Initial Access Payload Generator

image scaling attacks for multi-modal prompt injection

PoC demonstrating quadratic DoS in Elixir html_sanitize_ex via crafted HTML; includes timing benchmarks, remote exploitation curl, and verification…

Modern PIC implant for Windows (64 & 32 bit)

A simple ptrace-less shared library injector for x64 Linux

Collection of VBA macro published in our twitter / blog

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.

A new simple and powerfull packer for malware

A payload delivery system which embeds payloads in an executable's icon file!

PoC-Malware-TTPs

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

Inject DLLs into the explorer process using icons

XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE PoC mirror — WordSec, MIT; for authorized security testing