
GhostDriver
yet another AV killer tool using BYOVD

yet another AV killer tool using BYOVD

This repo covers some code execution and AV Evasion methods for Macros in Office documents

UEFI rootkit under development focusing on privilege escalation, C2 integration, and anti-EDR/AV evasion for real-world malware deployment.

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

A tool to transform Chromium browsers into a C2 Implant

For when DLLMain is the only way

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

macOS Initial Access Payload Generator

Tools for discovery and abuse of COM hijacks

Windows Local Privilege Escalation via CdpSvc service (Writeable SYSTEM path Dll Hijacking)

CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking

Tools for maintaining access to systems and proof-of-concept demonstrations.

Establishes persistence on a Linux system by creating a udev rule that triggers the execution of a specified payload (binary or script)

poc for CVE-2025-24252 & CVE-2025-24132

Execute a payload at each right click on a file/folder in the explorer menu for persistence

PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.

WPTaskScheduler RPC Persistence & CVE-2024-49039 via Task Scheduler

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.