
ShellcodeFluctuation
An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

A small reverse shell for Linux & Windows

powerful auto-backdooring utility

Lilith - Foundational reverse engineering resource for cybersecurity entrepreneurs in C++

A tool to transform Chromium browsers into a C2 Implant

A light-weight first-stage C2 implant written in Nim (and Rust).


A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

Automated Linux evil maid attack

Hershell is a simple TCP reverse shell written in Go.

some gadgets about windows process and ready to use :)

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.

Various ways to execute shellcode

PE loader with various shellcode injection techniques

Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks by spawning…

A fully featured Windows backdoor that uses Gmail as a C&C server