
donut
Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

New generation of wmiexec.py

C2/post-exploitation framework

Azazel is a userland rootkit based off of the original LD_PRELOAD technique from Jynx rootkit. It is more robust and has additional features, and…

Amsi Bypass payload that works on Windwos 11

RAT-el is an open source penetration test tool that allows you to take control of a windows machine. It works on the client-server model, the server…

Windows x64 kernel mode rootkit process hollowing POC.

BOF combination of KillDefender and Backstab

some python3 functions to add spreading features to any python backdoor

Bifrost C2. Open-source post-exploitation using Discord API

Proof of concept for CVE-2024-7479

An authentication bypass was recently discovered (https://www.webarxsecurity.com/vulnerability-infinitewp-client-wp-time-capsule/) on WP Time Capsule…


Kernel-mode syscall wrapper with Zydis-based dynamic pattern finding for Windows 10/11


This is an exploit for CVE-2017-7047, Works on 10.3.2 and below.