
DInvoke_rs
Dynamically invoke arbitrary unmanaged code

Dynamically invoke arbitrary unmanaged code

PowerShell Script to automatically abuse the BadSuccessor vulnerability (CVE-2025-53779)

This cheatsheet maps common impacket workflows to their modern alternatives

Header-only Windows x64 indirect syscall library. Zero CRT, zero IAT, VEH anti-BP, AMSI/ETW bypass, W^X memory, per-call dynamic stubs.

Arbitrary Function Call Exploit using the ThrottleStop driver

C# tool that enumerates running processes, loaded DLLs, installed services, and drivers to detect the presence of AV, EDR, and logging products,…

Invoke-ArgFuscator is an open-source, cross-platform PowerShell module that helps generate obfuscated command-lines for common system-native…

PowerShell tool for transferring files in restricted environments (Citrix, RDP, VNC, Guacamole) via clipboard, Base64 chunks, keystrokes, or OCR…

Simple & Powerful PowerShell Script Obfuscator

DNS data exfiltrator that sends payloads over UDP/TCP with configurable query size, random delay, and random domains to evade detection during red…

Penetration testing utility and antivirus assessment tool.

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

Dynamic Windows API resolver and unhooker that detects and restores hooked functions (IAT, EAT, inline patches) to invoke unmonitored system calls…

powershell tool for VM evasion


Empire is a PowerShell and Python post-exploitation agent.

Encodes a PowerShell script in the pixels of a PNG file and generates a oneliner to execute

PowerShell Obfuscator