
OSRipper
AV evading cross platform Backdoor and Crypter Framework with a integrated lightweight webUI

AV evading cross platform Backdoor and Crypter Framework with a integrated lightweight webUI

Evade behavioral analysis by executing malicious code within trusted Microsoft call stacks, patchless hooking library IAT/EAT.

Analysis and exploitation of CVE-2017-3066, a Java deserialization RCE in Adobe ColdFusion's BlazeDS library, with Suricata detection rules and…

Analysis, detection, and mitigation of CVE-2023-20198 exploitation in Cisco IOS XE – QUB CSC3064 Network Security Assessment

Creation of multiple Malware tools consisting of evasion, enumeration and exploitation


A collection of awesome penetration testing resources, tools and other shiny things

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.

Domain-fronted HTTP/SOCKS5 proxy tunneling traffic through Google Apps Script with MITM TLS interception, HTTP/1-2 multiplexing, and DPI evasion.

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609,…


Killer is a super simple tool designed to bypass AV/EDR security tools using various evasive techniques and used by Patchwork group.

🐱💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a…

Python AV Evasion Tools

A new approach to Browser In The Browser (BITB) without the use of iframes, allowing the bypass of traditional framebusters implemented by login…