
sliver
Adversary Emulation Framework

Adversary Emulation Framework

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

PoCs and tools for investigation of Windows process execution techniques

Armor is a simple Bash script designed to create encrypted macOS payloads capable of evading antivirus scanners.

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Threadless Process Injection using remote function hooking.

C# Reflective loader for unmanaged binaries.

MD5-Monomorphic Shellcode Packer - all payloads have the same MD5 hash

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Reverse Shell Detection with Machine Learning


Modern PIC implant for Windows (64 & 32 bit)

SharpSploit is a .NET post-exploitation library written in C#

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode