
Christmas
PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

PoCs and tools for investigation of Windows process execution techniques

A memory-based evasion technique which makes shellcode invisible from process start to end.

Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a…

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

InjectProc - Process Injection Techniques [This project is not maintained anymore]

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

some gadgets about windows process and ready to use :)

Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks by spawning…

Cobalt Strike BOF - Bypass AMSI in a remote process with code injection.

Inject DLLs into the explorer process using icons

A shellcode function to encrypt a running process image when sleeping.

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

PE injection technique that overwrites a suspended process's executable with a payload, enabling code execution under a benign process identity.

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…