
NimShellcodeFluctuation
ShellcodeFluctuation PoC ported to Nim

ShellcodeFluctuation PoC ported to Nim

RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging

A POC to disable TamperProtection and other Defender / MDE components

Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes

D/Invoke implementation in Nim

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

Hides reflective payloads in GPU memory via CUDA APIs, wiping host memory during sleep and using a VEH handler to restore executable memory, evading…

Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.

Command-line utility for Windows that enables SeTakeOwnershipPrivilege and modifies file ownership to the current user, granting access to otherwise…

A PoC implementation for dynamically masking call stacks with timers.


Terminate AV/EDR leveraging BYOVD attack

PoC for Windows privilege escalation and code injection using OfficeClickToRun RPC and undocumented shim manipulation to inject DLLs into SYSTEM…

Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap