
Lastenzug
Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

A proof of concept for abusing exception handlers to hook and bypass user mode EDR hooks.

Source generator to add D/Invoke and indirect syscall methods to a C# project.

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then reflective load…

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass,…

CTT-PAN-OS-Exploit – CVE-2024-3400 (CVSS 10.0) with Convergent Time Theory enhancement. Uses α = 0.0302011 temporal dispersion, 33-layer phase…

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

Evasion kit for Cobalt Strike

Performing Indirect Clean Syscalls

A BOF that runs unmanaged PEs inline

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.