
OffensiveVBA
This repo covers some code execution and AV Evasion methods for Macros in Office documents

This repo covers some code execution and AV Evasion methods for Macros in Office documents

LD_PRELOAD-based tool that hijacks gcc to inject malicious code into binaries during linking, enabling stealthy backdoor deployment without source…

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

Writeup and code for CVE-2025-11492, CVE-2025-11493 - RCE in ConnctWise Automate RMM via Adversary-in-the-Middle

Generate Payloads and Control Remote Machines. [Discontinued]

LSTAR - CobaltStrike Translated to EN


Toolbox containing research notes & PoC code for weaponizing .NET's DLR

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

Collection of Offensive C# Tooling

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Tools for discovery and abuse of COM hijacks

[AI-assisted] Root method for Lenovo IdeaTab A1000G (MT8317, kernel 3.4.0, Android 4.1) via CVE-2016-5195 (Dirty COW)

macOS persistence mechanism scanner with code signature verification and timeline tracking.

Pupy is an opensource, multi-platform (Windows, Linux, OSX, Android), multi function RAT (Remote Administration Tool) mainly written in python. It…

Python botnet and backdoor

NTP-based backdoor for hardened networks, delivering and executing arbitrary shellcode via spoofed NTP traffic with optional persistence as a Windows…