
DCVC2
Discord voice channel C2 framework for covert command and control operations. Transmits all data via RTP packets over voice channels, leaving no…

Discord voice channel C2 framework for covert command and control operations. Transmits all data via RTP packets over voice channels, leaving no…

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Cobalt Strike Beacon Object File that frees memory regions containing User Defined Reflective Loaders (UDRLs) to reduce post-exploitation memory…

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Exploit I discovered in October of 2022 with androids Package manager binary (pm) and the way it handled debugging flags, patched out by march 2023.…

AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64

Offensive Windows technique that bypasses EDR solutions by combining IAT hooking, dynamic SSN resolution, and indirect system calls to hide execution…

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

Technical analysis and proof-of-concept exploit for a symlink vulnerability in Apple's ManagedConfiguration framework, enabling unauthorized file…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

C# host-survey tool for offensive and defensive security, performing extensive safety checks on Windows systems including user, system, and network…

UEFI bootkit for Windows with Secure Boot bypass, kernel-level persistence, and encrypted HTTPS C2. Features HVCI/UAC bypass, API hooking, and…

Windows-based remote access trojan (RAT) for covert system control, payload delivery, and data exfiltration. Intended for authorized security…

PowerShell-based RAT using WMI for remote command execution, lateral movement, and C2 communication. Enables file operations, process management,…

Automates Windows domain Kerberos relay attacks to achieve local privilege escalation via RBCD, Shadow Credentials, or ADCS web enrollment, then…