
DeepSleep
A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

Framework for Digiduck Development Boards running ATTiny85 processors and micronucleus bootloader!

Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a…

Direct Memory Access (DMA) Attack Software

Custom PE loading and manipulation library for manual mapping, IAT hooking, memory dumping, and rebuilding imports for malware analysis and reverse…

The swiss army knife of LSASS dumping

EDRSandblast-GodFault

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

Manual kernel driver mapper for Windows x64 that abuses CVE-2025-8061 in Lenovo's LnvMSRIO.sys to perform a BYOVD attack, mapping PE64 drivers into…

Ping Exfiltration Command and Control (PiX-C2)

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

Dump the memory of a PPL with a userland exploit

Linux kernel local privilege escalation PoC for CVE-2026-68121, chaining PPPoE, FUSE, and IP6GRE to corrupt kernel memory and gain root.