
blackpill
A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

Windows memory hacking library

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

A post-exploitation powershell tool for extracting juicy info from memory.

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

Dump cookies and credentials directly from Chrome/Edge process memory

Cobalt Strike UDRL for memory scanner evasion.

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly.

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

A PoC Java Stager which can download, compile, and execute a Java file in memory.

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

Collection of Brute Ratel C4 BOFs for Windows post-exploitation: process memory access, NetNTLMv2 hash retrieval, contact harvesting, and…

A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.