
Dirty-Vanity
A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

some gadgets about windows process and ready to use :)

Kernel exploit for Xbox SystemOS using CVE-2024-30088

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

From XSS to RCE 2.75 - Black Hat Europe Arsenal 2017 + Extras

Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.

Various ways to execute shellcode

PE loader with various shellcode injection techniques

Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks by spawning…


Compromising the macOS Kernel through Safari by Chaining Six Vulnerabilities

CVE-2021-1732 Exploit

Collection of bypass gadgets to extend and wrap ysoserial payloads

Generates cross-platform polyglot payloads (Bash/PowerShell) for command execution, reverse shells, and binary execution, with configurable delay and…

Blaze Telegram Backdoor Toolkit is a post-exploitation tool that leverages the infrastructure of Telegram as a C&C

XLL Phishing Tradecraft

A way to delete a locked file, or current running executable, on disk.