
VAXD
Lightweight Windows disassembler, PE inspection and patch-assistance tool for native EXE/DLL files.

Lightweight Windows disassembler, PE inspection and patch-assistance tool for native EXE/DLL files.

InfectPE - Inject custom code into PE file [This project is not maintained anymore]


Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler,…

PolyEngine is an evasive PE packer designed for CTF challenges and low-level Windows security education. It focuses on bypassing EDR and AV…

Practical Windows malware development course: API hashing, DLL sideloading, shellcode execution, PE manipulation, payload hosting, and delivery labs.

A minimal PE mapper that loads DLLs straight from memory and calls into a clean plugin interface, no LoadLibrary needed.

Rust-based Windows PE manual loader that maps and executes x86/x64 executables from memory, demonstrating internal loader behavior and PE structure…

Implementing Ghostly-Hollowing using tampered syscalls for remote PE injection

A monthly Windows PE baseline dataset for Cyber security researchers

Technical research on a UEFI Secure Boot bypass caused by an unsafe custom PE loader, including root-cause analysis, exploitation workflow, and an…

Proof-of-concept exploit for CVE-2026-31431, modernized from the original Copy Fail PE exploit. Demonstrates the vulnerability for educational…

A variation of ProcessOverwriting to execute shellcode on an executable's section

A foundational C library for building operationally credible offensive capabilities

Evidence-focused malware reverse engineering with deep PE/.NET inspection, Ghidra reconstruction, AI cross-checks, YARA, and ELF debugging

CVE-2025-8088 exploitation chain + Quasar C2 multi-stage payload delivery