
mkPIVM
Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

Runtime process analysis and memory hacking MCP server for AI agents. Supports dynamic extension loading, read-only mode, audit logging, and…

Local PE injection technique using hardware breakpoints and vectored exception handling to manipulate DLL loading and execute arbitrary payloads, as…

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

Proof-of-Concept for CVE-2025-8088 vulnerability in WinRAR (path traversal via ADS)

Proof-of-concept exploit for WinRAR CVE-2025-8088 that drops a VBScript payload into the startup directory for persistence upon reboot.

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Proof-of-concept exploit for CVE-2025-0411, demonstrating Mark-of-the-Web bypass in 7-Zip to enable arbitrary code execution via crafted archives…

Some Rust program I wrote while learning Malware Development

Proof-of-concept exploit for CVE-2024-3400, demonstrating command injection in Palo Alto PAN-OS with a Python-based backdoor, persistence via…

Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors

some gadgets about windows process and ready to use :)

Legacy Windows RAT source code with client/server backdoor architecture, configurable payload builder, and full remote control for malware research.

it is malicious technique used by hackers to hide malware payloads in an encoded script in a specially crafted HTML attachment or web page

Malicious DOCX generator exploiting CVE-2021-40444 for remote code execution via crafted Office documents, with integrated hosting server for payload…

Proof-of-concept exploit for CVE-2022-30190 (Follina) targeting Microsoft PowerPoint via malicious OLE object in slide XML, with a custom HTML…

A simple script to obfuscate batch(bat) code easily

PE loader with various shellcode injection techniques