
freeBokuLoader
A simple BOF that frees UDRLs

A simple BOF that frees UDRLs

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then reflective load…

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…

Crystal Palace library for proxying Nt API calls via the Threadpool

DNS over HTTPS targeted malware (only runs once)

Remove API hooks from a Beacon process.

Indirect syscalls + DInvoke made simple.

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Generate Caddy redirector configs from Cobalt Strike or Sliver C2 profiles.

"Two-Face" Rust binary on Linux

LSTAR - CobaltStrike Translated to EN

Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…

POC code according to trendmicro's research

Header bypass for CVE-2025-55182 (React Server Components RCE).

CS_SleepMask