
charlotte
c++ fully undetected shellcode launcher ;)

c++ fully undetected shellcode launcher ;)

pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully…

HTTP Request Smuggling over HTTP/2 Cleartext (h2c)

Tests your WAF with +160 payloads

Cooolis-ms是一个包含了Metasploit Payload Loader、Cobalt Strike External C2 Loader、Reflective DLL injection的代码执行工具,它的定位在于能够在静态查杀上规避一些我们将要执行且含有特征的代码,帮助红队人员更方便快…


A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques

PyMultitor - Python Multi Threaded Tor Proxy

C++ shellcode injection technique using XOR encryption and UUID string conversion to bypass Windows Defender, with function call obfuscation and…

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

A sophisticated, covert Windows-based credential dumper using C++ and MASM x64.

This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context…

Malformed ZIP archive that evades antivirus detection by declaring Method=0 (stored) while containing DEFLATE-compressed payload.

Reflective x64 PE/DLL Loader implemented using Dynamic Indirect Syscalls

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Run Powershell without software restrictions.

A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.