
MemFiles
A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk

A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk


Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

In-memory Python loader for Beacon Object Files that executes COFF payloads, with packed/raw argument support for red-team and post-exploitation…

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

A proof of concept injectable C++ dll, that uses naked inline hooking and direct memory modification to change your TeamViewer permissions.

A BOF designed to inspect processes memory and addresses

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Demo project how to bypass the disable_functions security control of PHP on Linux

BYOVD Remove PPL for 24H2 and 25H2

Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing…

A variation of ProcessOverwriting to execute shellcode on an executable's section

Reflective PE packer.

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors
