
LdrLockLiberator
For when DLLMain is the only way

For when DLLMain is the only way

Blaze Telegram Backdoor Toolkit is a post-exploitation tool that leverages the infrastructure of Telegram as a C&C

A way to delete a locked file, or current running executable, on disk.

DBC2 (DropboxC2) is a modular post-exploitation tool, composed of an agent running on the victim's machine, a controler, running on any machine,…

A Bind Shell Using the Fax Service and a DLL Hijack

RSPET (Reverse Shell and Post Exploitation Tool) is a Python based reverse shell equipped with functionalities that assist in a post exploitation…

Inject DLLs into the explorer process using icons

CVE-2023-34312

Meterpreter Paranoid Mode - SSL/TLS connections

Remote Recon and Collection

Activation Context Hijacking Evasion Tool

Kernel exploit for Xbox SystemOS using CVE-2024-30088

Loads and runs ELF objects entirely in memory across x86_64/x86 Linux systems, resolving libc symbols at runtime for stealthy post-exploitation…

A stealthy Python based Windows backdoor that uses Github as a command and control server

Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin…

Windows x64 handcrafted token stealing kernel-mode shellcode

Tools for discovery and abuse of COM hijacks

A cross-platform implant written in Nim