
APTs-Adversary-Simulation
Realistic APT adversary simulation campaigns with custom C2 frameworks, backdoors, stagers, and bootloaders mirroring state-sponsored TTPs for red…

Realistic APT adversary simulation campaigns with custom C2 frameworks, backdoors, stagers, and bootloaders mirroring state-sponsored TTPs for red…

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

Windows code injection PoC that abuses the fork API to execute ntdll-based shellcode in a forked process and bypass EDRs.

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

Inject DLLs into the explorer process using icons

A delicious, but malicious SSL-VPN server 🌮

Generates macOS initial access payloads for Mythic C2: installer packages, Office macros, armed PDFs, disk images, and weaponized PIP/Ruby/NPM…

Hides reflective payloads in GPU memory via CUDA APIs, wiping host memory during sleep and using a VEH handler to restore executable memory, evading…

Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap

A simple ptrace-less shared library injector for x64 Linux

Obfuscates PE binaries into fileless loaders that add PE sections, unhook ntdll, and exploit signed drivers to remove kernel callbacks for EDR…

Collection of VBA macro published in our twitter / blog

Windows kernel-mode COFF loader for executing x64 kernel COFF payloads, supports NTOSKRNL/SSDT imports and client-driven loading for red-team…

Executes .NET assemblies from Office VBA via AppDomain.ExecuteAssembly, automating COM objects and bypassing AccessVBOM for local or remote assembly…

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.