
wnfexec
WNF Code Execution Library Using C#

WNF Code Execution Library Using C#

PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

A credential extraction BOF for Veeam Backup and Replication and Veeam One

A utility to use the usermode shellcode from the DOUBLEPULSAR payload to reflectively load an arbitrary DLL into another process, for use in testing…

Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.

Collection of VBA macro published in our twitter / blog

A PoC project for embedding shellcode to Hint/Name Table

REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in…

WPTaskScheduler RPC Persistence & CVE-2024-49039 via Task Scheduler

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

DLL sideloading/proxying with Nim!

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

HTTP Server serving obfuscated Powershell Scripts/Payloads

Local privilege escalation exploit for CVE-2020-1066 targeting Windows 7 and Server 2008 R2. Leverages arbitrary file replacement via Windows…

A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…