
Windows-SignedBinary
Mutates signed Windows binaries to retain valid catalog signatures while changing file hashes, bypassing hash-based endpoint blocks and exposing…

Mutates signed Windows binaries to retain valid catalog signatures while changing file hashes, bypassing hash-based endpoint blocks and exposing…

A BOF that runs unmanaged PEs inline

Remove API hooks from a Beacon process.

Remove API hooks from a Beacon process.

Embed a payload inside a PNG file

"Two-Face" Rust binary on Linux

Flex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload

Convert Cobalt Strike profiles to modrewrite scripts

Apache RewriteRule to mitigate potential DoS attack via Wordpress wp-admin/load-scripts.php file

Exploit for CVE-2023-23397 Outlook NTLM hash leak via malicious calendar invitations. Includes PowerShell weaponization, Responder integration, and…

Spoof file icons and extensions in Windows

Tunnel TCP connections through a file

Suricata and Bro detection rules for CVE-2020-1938 (Ghostcat) Tomcat AJP file read vulnerability, enabling network-level monitoring and alerting.

Runtime tracer for Node.js malware analysis that hooks core modules, logs calls, spoofs anti-analysis checks, and captures file writes and HTTP…

AppLocker-Based EDR Neutralization

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass,…

Super UEFIinSecureBoot Disk: Boot any OS or .efi file without disabling UEFI Secure Boot