
MalDev
Creation of multiple Malware tools consisting of evasion, enumeration and exploitation

Creation of multiple Malware tools consisting of evasion, enumeration and exploitation

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

THorse is a RAT (Remote Administrator Trojan) Generator for Windows/Linux systems written in Python 3.

Redirects EDR working folders using a Bind Filter (bindflt.sys) to bypass endpoint detection, corrupt EDR services, or replace with…

Permanently disable EDRs as local admin

PostShell - Post Exploitation Bind/Backconnect Shell


A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated…

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Comprehensive red teaming notes covering offensive security techniques including code injection, defense evasion, lateral movement, and persistence,…

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…

"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence.…

Analysis and exploitation of CVE-2025-4275 (Hydr0ph0bia), a Secure Boot trust-chain weakness where firmware variables are used to introduce…