
azazel
Azazel is a userland rootkit based off of the original LD_PRELOAD technique from Jynx rootkit. It is more robust and has additional features, and…

Azazel is a userland rootkit based off of the original LD_PRELOAD technique from Jynx rootkit. It is more robust and has additional features, and…

Amsi Bypass payload that works on Windwos 11

RAT-el is an open source penetration test tool that allows you to take control of a windows machine. It works on the client-server model, the server…

An authentication bypass was recently discovered (https://www.webarxsecurity.com/vulnerability-infinitewp-client-wp-time-capsule/) on WP Time Capsule…

This is an exploit for CVE-2017-7047, Works on 10.3.2 and below.

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Bifrost C2. Open-source post-exploitation using Discord API

Proof of concept for CVE-2024-7479


Windows x64 kernel mode rootkit process hollowing POC.

C2/post-exploitation framework

New generation of wmiexec.py

BOF combination of KillDefender and Backstab

some python3 functions to add spreading features to any python backdoor

Kernel-mode syscall wrapper with Zydis-based dynamic pattern finding for Windows 10/11
