
Hollow
A shellcode loader generator with support for multiple injection techniques, built for red team engagements.

A shellcode loader generator with support for multiple injection techniques, built for red team engagements.

Cross-platform syscall-powered implant & C2 — direct syscalls (Win), raw syscalls (Linux), HTTPS/DNS/ICMP channels. No winapi layer.

A Bumblebee-inspired Crypter

An extensible, end-to-end encrypted reverse shell that works across networks without port forwarding.

Abuses the Microsoft-signed tlscsp.dll LOLBin to run RC4 encrypt/decrypt via LsCsp_EncryptHwid, patching the hardcoded key in memory for BYOK…

HTTPS C&C Framework with encrypted beacons, web dashboard, and Windows agent.

Drop any Windows DPAPI artifact and it identifies the format and the exact master key it needs, then decrypts once you supply the key. Offline, CLI +…

DDoor - cross platform backdoor using dns txt records

Serving payloads only to allowed processes using Windows projected file system feature

Decrypt and re-encrypt Laravel session cookies to exploit insecure PHP deserialization for remote code execution.

A PoC on how to use a Compute Shader as Payload

Reverse-engineered Easy Anti-Cheat kernel driver bypass that intercepts memory allocation to suppress violation packets, with report decryption…

Exploitation and Post-Exploitation Multitool for Palo Alto PAN-OS Systems affected by vulnerabilities CVE-2024-0012 and CVE-2024-9474

encrypted-linux-kernel-modules

Mythic C2 profile that tunnels Athena and Apollo agent traffic through Telegram bot-to-bot messages, bridging encrypted payloads to Mythic via its…

Remote Windows keylogger with AES-256 encrypted keystroke exfiltration via configurable callback intervals and a companion Python server for log…

YellowKey | BitLocker Bypass Vulnerability (CVE-2026-45585)

CVE-2022-27499