
Quasar
Remote Administration Tool for Windows

Lilith - Foundational reverse engineering resource for cybersecurity entrepreneurs in C++

Cobalt Strike BOF that exploits a Windows Protected Process Light bypass to dump protected processes, enabling credential access from LSASS.

This is the tool to dump the LSASS process on modern Windows 11

Lightweight RAT providing silent remote command-line access, hidden file download/execution, and persistence mechanisms for Windows systems.…

Windows privilege escalation exploit abusing a TOCTOU in Code Integrity to bypass Protected Process Light, execute as WinTcb-Light, and dump…

A light-weight first-stage C2 implant written in Nim (and Rust).

Proof-of-concept C exploit that runs a DLL with WinTcb-Light protection from userland, demonstrating a Windows privilege-escalation primitive and…