
memdumper
Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

Windows Defender 0day proof-of-concept demonstrating a patch bypass for CVE-2026-69414, targeting Windows 11 25H2 and Server 2025 to evade endpoint…

ThrottleStop.sys Arbitrary Physical Memory R/W

Reuse open handles to dynamically dump LSASS.

A shellcode function to encrypt a running process image when sleeping.

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

collection of apis used in malware development


Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles


NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs

PowerSploit - A PowerShell Post-Exploitation Framework

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.