
msmq_re
Proof-of-concept exploit for the MSMQ QueueJumper RCE, crafting malformed packets to trigger unauthenticated remote code execution via the Message…

Proof-of-concept exploit for the MSMQ QueueJumper RCE, crafting malformed packets to trigger unauthenticated remote code execution via the Message…

Generate proxy DLLs that forward exports to a target DLL while loading a user-defined secondary DLL, enabling DLL hijacking and side-loading for red…

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

Custom firmware framework for PS Vita that patches the kernel, disables code-signing checks, and provides a hooking API for developing kernel and…

Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors

Some Rust program I wrote while learning Malware Development

Adaptive DLL hijacking / dynamic export forwarding - EAT preserve

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

weaponized radare2 vulnerability found by @CaptnBanana and blenk92

A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.

Malicious DOCX generator exploiting CVE-2021-40444 for remote code execution via crafted Office documents, with integrated hosting server for payload…

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…

Local PE injection technique using hardware breakpoints and vectored exception handling to manipulate DLL loading and execute arbitrary payloads, as…

Local privilege escalation exploit for CVE-2020-1066 targeting Windows 7 and Server 2008 R2. Leverages arbitrary file replacement via Windows…

Simple exploit for Easy RM to MP3 Converter 2.7.3.700 on Windows 7 32b.

Runtime process analysis and memory hacking MCP server for AI agents. Supports dynamic extension loading, read-only mode, audit logging, and…

ARM64 ELF Virtual Machine Protection System

Generates a proof-of-concept exploit for CVE-2024-27876, a libAppleArchive vulnerability, with technical write-up and implementation details.