
zombieant
Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.

Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.

Malware Configuration And Payload Extraction

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

Code Injection, Inject malicious payload via pagetables pml4.

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

"Reverse engineering analysis of a fileless Remcos RAT variant that injects into svchost.exe via Native API calls. Covers obfuscated payload…

Interactive browser-based lab simulating Chrome memory corruption vulnerabilities (CVE-2025-14765/14766) for safe security training, featuring…

ROP-based sleep obfuscation to evade memory scanners

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Re-implementation of VirtueSecurity's benigncertain-monitor

The swiss army knife of LSASS dumping

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

Hide memory artifacts using ROP and hardware breakpoints.

Beacon Object File for in-line LSASS credential extraction using the KslD.sys BYOVD technique. Extracts NT hashes and cleartext passwords from…

Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a…