
AntiVE-BehaviorWatch
Embedded GRU neural network for real-time human behavior verification via mouse movement analysis, detecting automated analysis systems, sandboxes,…

Embedded GRU neural network for real-time human behavior verification via mouse movement analysis, detecting automated analysis systems, sandboxes,…

Proof-of-concept exploit for PreAuth RCE in ManageEngine ServiceDesk Plus (CVE-2021-44077). Uploads and executes arbitrary Windows executables on…

Python framework for generating polymorphic Windows executables with multi-layer RC4 encryption, junkcode injection, and binary metadata spoofing to…

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

Cobalt Strike aggressor script implementing CVE-2020-0796 local privilege escalation via reflective DLL injection for Windows 10 and Server 1903/1909.

DLL hijacking proof-of-concept that weaponizes Microsoft Defender's MpClient.dll to load Cobalt Strike, demonstrating LockBit-style defense evasion.

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

Windows kernel exploit leveraging an arbitrary read vulnerability combined with Superfetch to achieve elevation of privilege from low integrity.

Lord Of Active Directory - automatic vulnerable active directory on AWS

Minimal proof-of-concept remote access trojan in Go using libp2p rendezvous and pubsub for self-healing command-and-control over Linux and Windows…

Proof-of-concept exploit for CVE-2024-49113 (LDAP Nightmare), a critical heap-based buffer overflow in Windows LDAP client (wldap32.dll). Includes a…

System-wide NTLM relay tool that hooks Windows authentication APIs to relay incoming NTLM connections, downgrade Kerberos, and dump NetNTLM hashes…

Generates initial access payloads abusing AddInProcess.exe via .NET deserialization, supporting HTA, VBA, JS, and CHM templates for in-memory code…

Multi-purpose proof-of-concept tool based on CPU-Z CVE-2017-15303

Rust-based PoC using Windows fibers to execute in-memory code stealthily, hiding payload stacks from EDR by switching between control and payload…

Open source pre-operation C2 server based on python and powershell

C++ self-Injecting dropper based on various EDR evasion techniques.

Tool to exploit CVE-2018-13341 and recover hidden account password on Crestron devices