
sliver
Adversary Emulation Framework

Adversary Emulation Framework

x64 Assembly injection engine using SROP and Zero-Copy Injection to bypass EDR/XDR and kernel monitors. Delivers XOR-encrypted payloads with minimal…

A simplified but capable penetration testing framework with exploit library, payload creation, and interactive console for authorized security testing

Stealthy DLL proxying implant for Microsoft Teams that injects AES-encrypted shellcode via unhooking techniques, providing persistent backdoor access…

NTP-based backdoor for hardened networks, delivering and executing arbitrary shellcode via spoofed NTP traffic with optional persistence as a Windows…

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

Pop shells like a master.

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

The Havoc Framework

My experiments in weaponizing Nim (https://nim-lang.org/)

Rust Weaponization for Red Team Engagements.

venom - C2 shellcode generator/compiler/handler

Hershell is a simple TCP reverse shell written in Go.

Nim-based encryption tool for obfuscating shellcode and payloads for evading Windows Defender.

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Undetectable Windows Payload Generation