
TinyLoad
Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Run Radmin VPN on Linux via Wine — custom driver, TAP bridge, zero packet loss

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

The perfect butler for pentesters, bug-bounty hunters and security researchers

ARM64 ELF Virtual Machine Protection System

Runtime process analysis and memory hacking MCP server for AI agents. Supports dynamic extension loading, read-only mode, audit logging, and…

Local PE injection technique using hardware breakpoints and vectored exception handling to manipulate DLL loading and execute arbitrary payloads, as…

Converts Windows EXE files into DLLs that export the original entry point, enabling DLL-style loading of arbitrary executables. Supports both 32-bit…

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

Generates a proof-of-concept exploit for CVE-2024-27876, a libAppleArchive vulnerability, with technical write-up and implementation details.

Some Rust program I wrote while learning Malware Development

A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…

🗜️ A packer for Windows x86 executable files written in C and Intel x86 Assembly. The new file after packing can obstruct reverse…

Generate proxy DLLs that forward exports to a target DLL while loading a user-defined secondary DLL, enabling DLL hijacking and side-loading for red…

Adaptive DLL hijacking / dynamic export forwarding - EAT preserve

Proof-of-concept exploit for CVE-2023-50564 targeting Pluck CMS, delivering a reverse shell via malicious module installation.

ReverShellGenerator - A tool to generate various ways to do a reverse shell