

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles

Load your driver like win32k.sys


PoCs and tools for investigation of Windows process execution techniques

NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs

PowerSploit - A PowerShell Post-Exploitation Framework

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

Single stub direct and indirect syscalling with runtime SSN resolving for windows.


C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

List of Awesome CobaltStrike Resources

Tools and PoCs for Windows syscall investigation.


Nim Library for Offensive Security Development

This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context…

Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.