
sliver
Adversary Emulation Framework

Adversary Emulation Framework

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

DropEngine provides a malleable framework for creating shellcode runners, allowing operators to choose from a selection of components and combine…

exploitdb // The official Exploit-Database repository

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

CVE-2020-0022 vulnerability exploitation on Bouygues BBox Miami (Android TV 8.0 - ARM32 Cortex A9)

CVE-2019-9729. Transferred from https://github.com/DoubleLabyrinth/SdoKeyCrypt-sys-local-privilege-elevation

Shellcode loader demonstrating multiple execution techniques including direct syscalls, IAT evasion, encrypted payloads, PPID spoofing, and code…

poc for CVE-2025-24252 & CVE-2025-24132

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

The Havoc Framework

A helper utility for creating shellcodes. Cleans MASM file generated by MSVC, gives refactoring hints.

Collection of various malicious functionality to aid in malware development

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…

Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing…

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…