
ThreadlessInject
Threadless Process Injection using remote function hooking.

Threadless Process Injection using remote function hooking.

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

Unauthenticated RCE exploit for Realtyna WPL < 5.3.0 that uploads a PHP webshell via hardcoded API key and executes arbitrary system commands.

Exploit for CVE-2026-17544: PHP bcmath OOB write converted into memory-only RCE, bypassing disable_functions and open_basedir with a runtime…

Loads and runs ELF objects entirely in memory across x86_64/x86 Linux systems, resolving libc symbols at runtime for stealthy post-exploitation…

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

Exploit for a Windows Defender race condition that escalates to SYSTEM via use-after-free, crashes MsMpEng.exe, spawns a hidden shell, and persists…

Nim library for dynamically invoking Windows API functions via PEB walks to avoid static imports and EDR hooking, enabling stealthier implants and…

Builds a malicious DLL that abuses Windows Task Scheduler's DLL search order to execute a script as SYSTEM during local privilege escalation.

Community payload loaders, scripts, and configurations for Brute Ratel C4, supporting red team command-and-control operations and payload deployment.

NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

Windows x64 handcrafted token stealing kernel-mode shellcode

Collection of VBA macro published in our twitter / blog

Autoelevate DLL search-order hijacking UAC bypass for x64 Windows 7–11, abusing 32-bit iscsicpl.exe via SysWOW64 to execute code without a UAC prompt.

In-memory COFF and BOF loader that parses, relocates, and executes object files, with optional Beacon Object File argument support for red-team…