
GoPurple
Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions


Proof-of-concept PHP 8 sandbox escape exploiting a use-after-free bug to bypass disable_functions and execute system commands on Unix-like systems.

CTF framework and exploit development library

Adversary Emulation Framework

Some setup scripts for security research tools.

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

Offensive Software Exploitation Course


A workshop about Malware Development

Notion as a platform for offensive operations

:cherry_blossom: Interactive shellcoding environment to easily craft shellcodes

Killer is a super simple tool designed to bypass AV/EDR security tools using various evasive techniques and used by Patchwork group.

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

EternalBlue suite remade in C/C++ which includes: MS17-010 Exploit, EternalBlue vulnerability detector, DoublePulsar detector and DoublePulsar…

Python AV Evasion Tools

CVE-2020-15368, aka "How to exploit a vulnerable driver"