
PiX-C2
Ping Exfiltration Command and Control (PiX-C2)

Ping Exfiltration Command and Control (PiX-C2)

A comprehensive educational repository demonstrating the evolution of a Windows reverse shell implant, from a simple proof‑of‑concept (v1.0) to a…

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Research code & papers from members of vx-underground.

A unique technique to execute binaries from a password protected zip

A memory-based evasion technique which makes shellcode invisible from process start to end.

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a…

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners…

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North…

Evaluation framework for studying LLM agents that automatically generate working exploits from vulnerability reports, bypassing modern security…

My first Android app: Launch Fusée Gelée payloads from stock Android (CVE-2018-6242)

Shellcode Loader with Indirect Dynamic syscall Implementation , shellcode in MAC format, API resolving from PEB, Syscall calll and syscall…