
CVE-2021-40444
Generates malicious DOCX documents exploiting CVE-2021-40444 (Microsoft Office RCE) with a hosted server for DLL payload delivery, based on…

Generates malicious DOCX documents exploiting CVE-2021-40444 (Microsoft Office RCE) with a hosted server for DLL payload delivery, based on…

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONLY.

Disassemble ANY files including .so (NDK, JNI), Windows PE(EXE, DLL, SYS, etc), linux binaries, libraries, and any other files such as pictures,…

EternalBlue suite remade in C/C++ which includes: MS17-010 Exploit, EternalBlue vulnerability detector, DoublePulsar detector and DoublePulsar…

PE loader with various shellcode injection techniques

Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Execute shellcode files with rundll32

Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

A scanner that files with compromised or untrusted code signing certificates written in python.

CVE-2025-56383-Proof-of-Concept

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

phpstudy dll backdoor for v2016 and v2018

This is working POC of CVE-2022-36271

IDA python script for deobfuscating Astaroth/Guildma injector DLL