
GoPurple
Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

My experiments in weaponizing Nim (https://nim-lang.org/)

ScareCrow - Payload creation framework designed around EDR bypass.

The swiss army knife of LSASS dumping

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

A memory-based evasion technique which makes shellcode invisible from process start to end.

InjectProc - Process Injection Techniques [This project is not maintained anymore]

Win32 and Kernel abusing techniques for pentesters

PoCs and tools for investigation of Windows process execution techniques

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a…

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

some gadgets about windows process and ready to use :)

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Windows x64 handcrafted token stealing kernel-mode shellcode

PE injection technique that overwrites a suspended process's executable with a payload, enabling code execution under a benign process identity.