
XLL_Phishing
XLL Phishing Tradecraft

XLL Phishing Tradecraft

A unique technique to execute binaries from a password protected zip

PowerShell Remote Download Cradle Generator & Obfuscator

Generate an obfuscated DLL that will disable AMSI & ETW

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

AutoPoC Generator HoneyPoC

🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs

A BYOSI (Bring-Your-Own-Script-Interpreter) Rapid Payload Deployment Toolkit

SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated…