
Christmas
PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Python3 utility for creating zip files that smuggle additional data for later extraction

A simple ptrace-less shared library injector for x64 Linux

Apply a divide and conquer approach to bypass EDRs

PE obfuscator with Evasion in mind


Port of Cobalt Strike's Process Inject Kit

Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

Collection of VBA macro published in our twitter / blog

Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.



Improved version of EKKO by @5pider that Encrypts only Image Sections

Resolves Windows APIs at runtime using vectored exception handlers and hashed lookups to hide imports and slow reverse engineering of offensive…

Cobalt Strike BOF collection for attacking Azure AD during red team operations, covering authentication, enumeration, and post-exploitation vectors.

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.