
OffensiveDLR
Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.

Documentation and reverse engineering of reCAPTCHA

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

Code Coverage Exploration Plugin for Ghidra

0-day malware detection for binaries, source & scripts (that doesn't suck)

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

A PoC Java Stager which can download, compile, and execute a Java file in memory.

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

Windows NT ioctl bruteforcer and modular fuzzer

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Pishi is a code coverage tool like kcov for macOS.

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

GNU IFUNC is the real culprit behind CVE-2024-3094

A tool for effective testing the binding layer of scripting languages