
AtlasLdr
Reflective x64 PE/DLL Loader implemented using Dynamic Indirect Syscalls

Reflective x64 PE/DLL Loader implemented using Dynamic Indirect Syscalls

Trojanize your payload - WinRAR (SFX) automatization - under Linux distros

Amsi Bypass payload that works on Windwos 11

Dynamic shellcode loader with sophisticated evasion capabilities

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles

A shellcode function to encrypt a running process image when sleeping.

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Nim Library for Offensive Security Development

Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8

different ntdll unhooking techniques : unhooking ntdll from disk, from KnownDlls, from suspended process, from remote server (fileless)

Execute shellcode files with rundll32

Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)

Improved version of EKKO by @5pider that Encrypts only Image Sections

A simple BOF that frees UDRLs

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

Crystal Palace library for proxying Nt API calls via the Threadpool

DNS over HTTPS targeted malware (only runs once)

"Two-Face" Rust binary on Linux