
PE-Obfuscator
PE obfuscator with Evasion in mind

PE obfuscator with Evasion in mind

Crystal port of GodPotato to abuse SeImpersonatePrivilege with indirect syscalls, dynamic API resolution and compile-time string obfuscation. Run…

Resolves Windows APIs at runtime using vectored exception handlers and hashed lookups to hide imports and slow reverse engineering of offensive…

A new simple and powerfull packer for malware

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

Hides reflective payloads in GPU memory via CUDA APIs, wiping host memory during sleep and using a VEH handler to restore executable memory, evading…

Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.

ShellcodeFluctuation PoC ported to Nim

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

macOS Initial Access Payload Generator

Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC

Modern PIC implant for Windows (64 & 32 bit)


Create Anti-Copy DRM Malware

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.

A payload delivery system which embeds payloads in an executable's icon file!

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

Weaponize DLL hijacking easily. Backdoor any function in any DLL.