
PowerSploit
PowerSploit - A PowerShell Post-Exploitation Framework

PowerSploit - A PowerShell Post-Exploitation Framework

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.


The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…

RemoteDLLInjector

Local Windows privilege escalation PoC for CVE-2026-66804: plants a COM DLL in a missing path to abuse Camera FrameServer and impersonate SYSTEM.

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.

Rusty Injection - Shellcode Reflective DLL Injection (sRDI) in Rust (Codename: Venom)

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

Extracting Clear Text Passwords from mstsc.exe using API Hooking.

Code Execution & Persistence in NETWORK SERVICE FAX Service

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file (DLL Hijacking)

Windows implant that steals RDP credentials via API hooking (Detours) and DLL injection, capturing usernames and passwords to a file for red-team…

A C2 post-exploitation framework

DLL Planting in the Slack 4.33.73 - CVE-2023-38820

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode