
donut
Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Execute shellcode files with rundll32

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

Randomly changes Win32/64 PE Files for 'safer' uploading to malware and sandbox sites.

Convert raw HTTP requests/responses into PCAP files for testing Snort IDS rules and network security analysis. Supports Docker deployment and…

Educational deep dive into macOS app bundles, plist files, and launchd process behavior, with offensive security notes on packaging payloads as .app…

Generates weaponized JPEG files exploiting CVE-2025-50165 (Windows Graphics RCE) with custom x64 shellcode, heap spray, ROP chain, and AV/EDR evasion…

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

AV/EDR evasion via direct system calls.

AV/EDR evasion via direct system calls.

RunPE implementation with multiple evasive techniques (2)

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.

Permanently disable EDRs as local admin

Runtime tracer for Node.js malware analysis that hooks core modules, logs calls, spoofs anti-analysis checks, and captures file writes and HTTP…

Zip file format fuzzer and multi-tool.