
Payload-Download-Cradles
This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context…

This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context…

C2Bridges allow developers to create new custom communication protocols and quickly utilize them within Covenant.

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

New Physics Disclosure This repository contains a full weaponized exploit for **CVE-2026-21509**, targeting the Windows Network File System (NFSv4.1)…

Educational deep dive into macOS app bundles, plist files, and launchd process behavior, with offensive security notes on packaging payloads as .app…

Hands-on red-team obfuscation workshop teaching AMSI bypass, ETW evasion, and payload obfuscation with PowerShell, Visual Basic, and C# to evade…

Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin resolution…

Penetration testing utility and antivirus assessment tool.

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

Shellcode injection technique. Given as C++ header, standalone Rust program or library.

Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors

HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.

How to spoof the command line when spawning a new process from C#.

A new simple and powerfull packer for malware

Shattered is a tool and POC for the new CrushedFTP vulns, CVE Exploit Script: CVE-2025-2825 vs CVE-2025-31161

Reverse Engineered based on CISA disclosure of new CVE

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…