
CrystalPotato
Crystal port of GodPotato to abuse SeImpersonatePrivilege with indirect syscalls, dynamic API resolution and compile-time string obfuscation. Run…

Crystal port of GodPotato to abuse SeImpersonatePrivilege with indirect syscalls, dynamic API resolution and compile-time string obfuscation. Run…

A delicious, but malicious SSL-VPN server 🌮

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

Modern PIC implant for Windows (64 & 32 bit)

Inject DLLs into the explorer process using icons

Threadless Process Injection using remote function hooking.

Create Anti-Copy DRM Malware

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.

A new simple and powerfull packer for malware

A payload delivery system which embeds payloads in an executable's icon file!

macOS Initial Access Payload Generator

Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.

PE obfuscator with Evasion in mind

PoC-Malware-TTPs


A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

ShellcodeFluctuation PoC ported to Nim