
Lilith
Lilith - Foundational reverse engineering resource for cybersecurity entrepreneurs in C++

Lilith - Foundational reverse engineering resource for cybersecurity entrepreneurs in C++

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

Offensive Software Exploitation Course

Driver Reverse & Exploitation

GPU IOMMU DMA exploit for Android devices that overwrites vdso.so with shellcode to escalate privileges and spawn a reverse root shell on Nexus 6p.

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

Windows memory hacking library

Ghost Framework is an Android post-exploitation framework that exploits the Android Debug Bridge to remotely access an Android device.

My musings with PowerShell

Remote Administration Tool for Android devices

Red team tool for EDR evasion: dynamically resolves syscall IDs, patches ntdll stubs, unhooks IAT hooks, and lists hooked APIs from major EDR vendors.

Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors

Collection of Offensive C# Tooling

Run Beacon Object Files (BOFs) outside Cobalt Strike by parsing 64-bit COFF object files, with Beacon-compatible argument generation and helper…

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

Win32 and Kernel abusing techniques for pentesters

Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a…

Android Remote Access Trojan