
FilelessPELoader
Loading Remote AES Encrypted PE in memory , Decrypted it and run it

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

RedCloudOS is a Cloud Adversary Simulation Operating System for Red Teams to assess the Cloud Security of Leading Cloud Service Providers (CSPs)

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting

Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

A simple ptrace-less shared library injector for x64 Linux

Apply a divide and conquer approach to bypass EDRs

Patch AMSI and ETW

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

See adversary, do adversary: Simple execution of commands for defensive tuning/research (now with more ELF on the shelf)

Bypass the Event Trace Windows(ETW) and unhook ntdll.

A payload delivery system which embeds payloads in an executable's icon file!

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Kernel-mode hook that intercepts, decrypts, and nullifies BEDaisy-to-service report traffic to suppress anti-cheat detection on UEFI and non-UEFI…

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

Proof-of-concept exploit for CVE-2026-22003 demonstrating Redis Lua sandbox escape via debug.sethook to execute arbitrary system commands.

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…