
Harald
An in-memory minimal CPU for agnostic on-the-fly protocols creation

An in-memory minimal CPU for agnostic on-the-fly protocols creation
This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

CS_SleepMask

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

A shellcode function to encrypt a running process image when sleeping.

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

collection of apis used in malware development

C++ library that retrieves and spoofs Windows syscall arguments using hardware breakpoints and exception handlers to subvert EDR telemetry.

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles

Single stub direct and indirect syscalling with runtime SSN resolving for windows.

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

Nim Library for Offensive Security Development

Call stack spoofing for Rust

Header-only C++17 library for evasive Windows development: compile-time API hashing, DLL unhooking, hardware breakpoint clearing, VEH removal, and…

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…