
ditto
Obfuscates PowerShell and JavaScript scripts using tree-sitter-based parsing with multiple configurable impostor profiles for stealth, size, and…

Obfuscates PowerShell and JavaScript scripts using tree-sitter-based parsing with multiple configurable impostor profiles for stealth, size, and…

Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 delivery variants

Golang malware development library

During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system…

SambaCry exploit and vulnerable container (CVE-2017-7494)

Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This…

takes shellcode bad-bytes and banishes them, returning cleaned shellcode with preserved functionalities

C++ library to load DLLs directly from memory without touching disk, with exception handling support, enabling stealthy code execution and evasion of…

Local PE injection technique using hardware breakpoints and vectored exception handling to manipulate DLL loading and execute arbitrary payloads, as…

Some Rust program I wrote while learning Malware Development

Flash sources for CVE-2018-15982 used by NK

Header-only Windows x64 indirect syscall library. Zero CRT, zero IAT, VEH anti-BP, AMSI/ETW bypass, W^X memory, per-call dynamic stubs.

Collection of various malicious functionality to aid in malware development

A Nim implementation of reflective PE-Loading from memory

Direct Memory Access (DMA) Attack Software

Custom PE loading and manipulation library for manual mapping, IAT hooking, memory dumping, and rebuilding imports for malware analysis and reverse…

Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819

Palo Alto - CVE-2026-0300 exploit