
DCVC2
Discord voice channel C2 framework for covert command and control operations. Transmits all data via RTP packets over voice channels, leaving no…

Discord voice channel C2 framework for covert command and control operations. Transmits all data via RTP packets over voice channels, leaving no…

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Automated Windows kernel exploit suite targeting CVE-2025-62215 (race condition + double-free). Integrates WinDbg JS for dynamic offset extraction…

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Cobalt Strike Beacon Object File that frees memory regions containing User Defined Reflective Loaders (UDRLs) to reduce post-exploitation memory…

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Exploit I discovered in October of 2022 with androids Package manager binary (pm) and the way it handled debugging flags, patched out by march 2023.…

Generates header/ASM files for direct Windows system calls to bypass AV/EDR user-mode hooks, enabling stealthy code execution and evasion in red team…

AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

iOS CVE-2018-4150 exploit proof-of-concept application demonstrating file system manipulation via tar extraction for security research.

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

UEFI bootkit for Windows with Secure Boot bypass, kernel-level persistence, and encrypted HTTPS C2. Features HVCI/UAC bypass, API hooking, and…

Generates header/ASM files for direct Windows system calls to bypass user-mode API hooks used by AV/EDR products, enabling stealthy red team…

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

Windows-based remote access trojan (RAT) for covert system control, payload delivery, and data exfiltration. Intended for authorized security…

During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system…