
UnhookMe
Dynamic Windows API resolver and unhooker that detects and restores hooked functions (IAT, EAT, inline patches) to invoke unmonitored system calls…

Dynamic Windows API resolver and unhooker that detects and restores hooked functions (IAT, EAT, inline patches) to invoke unmonitored system calls…

Abusing Reddit API to host the C2 traffic, since most of the blue-team members use Reddit, it might be a great way to make the traffic look legit.

Adaptive DLL hijacking / dynamic export forwarding

TrevorC2 is a legitimate website (browsable) that tunnels client/server communications for covert command execution.

🕳 godoh - A DNS-over-HTTPS C2

PoC Implementation of a fully dynamic call stack spoofer

Proof-of-concept obfuscation toolkit for C# post-exploitation tools

Proof-of-concept exploit for CVE-2022-39197, enabling remote code execution against CobaltStrike <= 4.7.1 via malicious SVG payload served over HTTP.

PE injection technique that overwrites a suspended process's executable with a payload, enabling code execution under a benign process identity.

C# obfuscator that bypass windows defender

Python interpreter for Cobalt Strike Malleable C2 Profiles. Allows you to parse, build and modify them programmatically.

A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementing page…

Various ways to execute shellcode

Proof-of-concept exploit for CVE-2022-39952 targeting Fortinet FortiNAC. Abuses keyUpload.jsp endpoint for arbitrary file write to deploy cron-based…

A way to delete a locked file, or current running executable, on disk.

基于Java实现的Shellcode加载器

Herramienta para evadir disable_functions y open_basedir

PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC