
astaroth-deobfuscator
IDA python script for deobfuscating Astaroth/Guildma injector DLL

IDA python script for deobfuscating Astaroth/Guildma injector DLL

Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC

Execute shellcode files with rundll32

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

phpstudy dll backdoor for v2016 and v2018

A comprehensive PowerShell-based SharePoint security monitoring solution with CVE-2025-53770 protection, advanced DLL analysis, threat detection, and…

CVE-2025-56383-Proof-of-Concept

Panoramic Dental Imaging software Stealthy Privilege Escalation Vulnerability

It shook the world in 2017 and has evolved into today’s CVE‑2025‑2776. Microsoft still relies on SMBv1, this article will explain how attackers have…

DLL Hijacking in Quickheal Total Security/ Internet Security/ Antivirus Pro (Installers)

Two versions of CVE-2017-8759 exploits

This is working POC of CVE-2022-36271

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

EternalBlue suite remade in C/C++ which includes: MS17-010 Exploit, EternalBlue vulnerability detector, DoublePulsar detector and DoublePulsar…