
CAPEv2
Malware Configuration And Payload Extraction

Malware Configuration And Payload Extraction

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

Code Injection, Inject malicious payload via pagetables pml4.

"Reverse engineering analysis of a fileless Remcos RAT variant that injects into svchost.exe via Native API calls. Covers obfuscated payload…

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

Advanced Linux Privilege Escalation research on CVE-2021-4034 (PwnKit). Features an optimized exploit with 7 polymorphic payload modes (Interactive…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

ROP-based sleep obfuscation to evade memory scanners

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Re-implementation of VirtueSecurity's benigncertain-monitor

The swiss army knife of LSASS dumping

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.

Hide memory artifacts using ROP and hardware breakpoints.

Beacon Object File for in-line LSASS credential extraction using the KslD.sys BYOVD technique. Extracts NT hashes and cleartext passwords from…