
slot2
UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

Proof-of-concept exploit for Citrix NetScaler CVE-2026-8452 that verifies pre-auth RCE by building shellcode and executing commands through a…

This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved…

D/Invoke implementation in Nim

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

Autoelevate DLL search-order hijacking UAC bypass for x64 Windows 7–11, abusing 32-bit iscsicpl.exe via SysWOW64 to execute code without a UAC prompt.

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

PoC MSI payload based on ASEC/AhnLab's blog post

Research code & papers from members of vx-underground.

Simple PoC Python agent to showcase Havoc C2's custom agent interface. Not operationally safe or stable. Released with accompanying blog post as a…

List of Awesome CobaltStrike Resources

A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development

This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context…

A collection of various and sundry code snippets that leverage .NET dynamic tradecraft

Tips on how to write exploit scripts (faster!)

Win32 and Kernel abusing techniques for pentesters