
artifacts-kit
Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Agent-based tool that collects OS, hardware, file, and hook data from internet-connected sandboxes via HTTPS exfiltration, aiding Red Team artifact…

proxychains ng (new generation) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more…

CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

Evade EDR's the simple way, by not touching any of the API's they hook.


A proof of concept for abusing exception handlers to hook and bypass user mode EDR hooks.

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)

Git Web Hook Tunnel for C2

Hook PasswordChangeNotify

Leverage WindowsApp createdump tool to obtain an lsass dump


Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution

CVE-2024-10220 Test repo

A submodule for exploiting CVE-2024-32002 vulnerability.
