
slot2
UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

Exploit for CVE-2026-17544: PHP bcmath OOB write converted into memory-only RCE, bypassing disable_functions and open_basedir with a runtime…


NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.

Apply a divide and conquer approach to bypass EDRs


Indirect syscalls + DInvoke made simple.

IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then reflective load…


BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions

The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.

Obex – Blocking unwanted DLLs in user mode

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

A python tool to map the access rights of network shares into a BloodHound OpenGraphs easily

Inject DLLs into the explorer process using icons

COFF file (BOF) for managing Kerberos tickets.