
pcileech
Direct Memory Access (DMA) Attack Software

Direct Memory Access (DMA) Attack Software

Linux post-exploitation framework with a UEFI bootkit that persistently and stealthily loads a Rust-based kernel module rootkit on modern Linux…

Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 delivery variants

Post-exploitation and evasion research toolkit for Linux.

A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

PCI Express DIY hacking toolkit for Xilinx SP605. This repository is also home of Hyper-V Backdoor and Boot Backdoor, check readme for links and info

A simple PoC demonstrating the vulnerability in the ThrottleStop.sys driver, showcasing arbitrary physical memory read and write capabilities, as…

Local PE injection technique using hardware breakpoints and vectored exception handling to manipulate DLL loading and execute arbitrary payloads, as…

SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using…

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

This is a proof-of-concept of malicious software running inside of ModSecurity WAF.

Some Rust program I wrote while learning Malware Development

CVE-2024-43451 is a Windows NTLM vulnerability that allows an attacker to force authentication and capture NTLM hashes by using malicious shortcuts.

MAL-002: Force System Restart via Installed Windows MSIs

Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors

A small utility to translate NTDS.dit files to SQLite format.