
GoPurple
Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…



An Interactive Binary Patching Plugin for IDA Pro

A Ruby framework designed to aid in the penetration testing of WordPress systems.

PoC - Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (Scanner and Exploit)

Proof-of-concept PHP 8 sandbox escape exploiting a use-after-free bug to bypass disable_functions and execute system commands on Unix-like systems.

Some setup scripts for security research tools.

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

Rust Weaponization for Red Team Engagements.

Offensive Software Exploitation Course

A tool to abuse Exchange services

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

AV/EDR evasion via direct system calls.

Polymorphic binary encoder for offensive security payloads. Encodes shellcode with LFSR-based feedback loop, garbage instruction injection, and…