
CobaltWhispers
CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

Educational deep dive into macOS app bundles, plist files, and launchd process behavior, with offensive security notes on packaging payloads as .app…

Execute shellcode files with rundll32

RunPE implementation with multiple evasive techniques (2)

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

Permanently disable EDRs as local admin

Generates weaponized JPEG files exploiting CVE-2025-50165 (Windows Graphics RCE) with custom x64 shellcode, heap spray, ROP chain, and AV/EDR evasion…

Runtime tracer for Node.js malware analysis that hooks core modules, logs calls, spoofs anti-analysis checks, and captures file writes and HTTP…

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

Zip file format fuzzer and multi-tool.

Randomly changes Win32/64 PE Files for 'safer' uploading to malware and sandbox sites.

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

AV/EDR evasion via direct system calls.

Convert raw HTTP requests/responses into PCAP files for testing Snort IDS rules and network security analysis. Supports Docker deployment and…

AV/EDR evasion via direct system calls.

A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.