
ContextMenuHijack
Execute a payload at each right click on a file/folder in the explorer menu for persistence

Execute a payload at each right click on a file/folder in the explorer menu for persistence

A python based https remote access trojan for penetration testing

WNF Code Execution Library Using C#

PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

Linux post-exploitation framework with a UEFI bootkit that persistently and stealthily loads a Rust-based kernel module rootkit on modern Linux…

PHP 7 and safe-build Update of the popular C99 variant of PHP Shell.

A credential extraction BOF for Veeam Backup and Replication and Veeam One

Collection of VBA macro published in our twitter / blog

A utility to use the usermode shellcode from the DOUBLEPULSAR payload to reflectively load an arbitrary DLL into another process, for use in testing…

Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.

POC for RCE using vulnerabilities described in VMSA-2023-0001

Beacon Object File implementation of Event Viewer deserialization UAC bypass

REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in…

WPTaskScheduler RPC Persistence & CVE-2024-49039 via Task Scheduler

DLL sideloading/proxying with Nim!

Generate a proxy dll for arbitrary dll

PostShell - Post Exploitation Bind/Backconnect Shell