
TinyLoad
Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Manual kernel driver mapper for Windows x64 that abuses CVE-2025-8061 in Lenovo's LnvMSRIO.sys to perform a BYOVD attack, mapping PE64 drivers into…

Pop shells like a master.

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

A workshop about Malware Development

SHAREM is a shellcode analysis framework, capable of emulating more than 45,000 WinAPIs and virutally all Windows syscalls. It also contains its own…

A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.

PostShell - Post Exploitation Bind/Backconnect Shell

Linux Shared Library to Shellcode Loader

exploitdb-bin-sploits // Exploit-Database's binary exploits (what was located in the /sploits directory)

CVE-2024-6387 POC (Currently being edited)

SambaCry (CVE-2017-7494) exploit for Samba | bind shell without Metasploit