
DccwBypassUAC
Windows 8.1 and 10 UAC bypass abusing WinSxS in "dccw.exe".

Windows 8.1 and 10 UAC bypass abusing WinSxS in "dccw.exe".

参考Gh0st源码,实现的一款PC远程协助软件,拥有远程Shell、文件管理、桌面管理、消息发送等功能。

This repository contains scripts, configurations and deprecated payload loaders for Brute Ratel C4 (https://bruteratel.com/)

Hides reflective payloads in GPU memory via CUDA APIs, wiping host memory during sleep and using a VEH handler to restore executable memory, evading…

Executes position independent shellcode from an encrypted zip

A BOF to automate common persistence tasks for red teamers

Golang reverse/bind shell generator

CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

DNS-Persist is a post-exploitation agent which uses DNS for command and control.


Multi-threaded Python reverse shell with payload generation, session management, keylogging, screensharing, and persistence for authorized…

Automatically spawn a reverse shell fully interactive for Linux or Windows victim

Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

Persistence by writing/reading shellcode from Event Log

A simple ptrace-less shared library injector for x64 Linux

Tools for maintaining access to systems and proof-of-concept demonstrations.