
RustyWater-ShellCode-Dropper
RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Collection of Offensive C# Tooling

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…