
NullGate
Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

Crystal Palace library for proxying Nt API calls via the Threadpool

Modern PIC implant for Windows (64 & 32 bit)

a small wiper malware programmed in c#

A Bumblebee-inspired Crypter

D/Invoke implementation in Nim

Create Anti-Copy DRM Malware

A new simple and powerfull packer for malware

A Streamlined FTP-Driven Command and Control Conduit for Interconnecting Remote Systems.

Generates HTML smuggling pages that embed and reconstruct files client-side via JavaScript, with payload encoding, chunking, obfuscation, and…

A payload delivery system which embeds payloads in an executable's icon file!

ShellcodeFluctuation PoC ported to Nim

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

PoC-Malware-TTPs

PoC MSI payload based on ASEC/AhnLab's blog post

Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.