
ThreadlessInject
Threadless Process Injection using remote function hooking.

Threadless Process Injection using remote function hooking.

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

Technical analysis and proof of concept for CVE-2026-59827, a critical unsafe Java deserialization vulnerability in Metabase leading to remote code…

Tools that trigger False Positive AV alerts

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

Collection of bypass gadgets to extend and wrap ysoserial payloads

Hide your payload into .jpg file

A payload delivery system which embeds payloads in an executable's icon file!

Simple dotnet Native AOT app that uses AsmResolver to convert shellcode to PE

macOS Initial Access Payload Generator

XSS payloads designed to turn alert(1) into P1

A new simple and powerfull packer for malware

Generates five .NET deserialization payload formats for CVE-2026-56158, delivers them over HTTP/SOAP/JSON endpoints, includes mock server, scanner,…

A powerful shell script for creating custom WSL (Windows Subsystem for Linux) distributions with embedded payloads.

Generate Proxy DLLs in Rust

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…
