
donut
Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with…

Converts PE into a shellcode

IDA Pro utilities from FLARE team

A tool to abuse Exchange services

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

SharpSploit is a .NET post-exploitation library written in C#

Reflective PE packer.

Converts a EXE into DLL

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners…

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs

Shellcode Compiler

Multi-cipher shellcode encryptor and obfuscator with automatic output conversion to C, C#, Rust, Nim, Python, and more. Supports ROT, XOR, RC4, AES,…

NTP-based backdoor for hardened networks, delivering and executing arbitrary shellcode via spoofed NTP traffic with optional persistence as a Windows…

A fully featured backdoor that uses Twitter as a C&C server

Polymorphic encryptor that transforms shellcode, PE, and COFF files into obfuscated, position-independent payloads with RC4 and random block cipher…

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.