
sliver
Adversary Emulation Framework

Adversary Emulation Framework

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

PoCs and tools for investigation of Windows process execution techniques

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

C# Reflective loader for unmanaged binaries.

Threadless Process Injection using remote function hooking.


A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

Reverse Shell Detection with Machine Learning

Modern PIC implant for Windows (64 & 32 bit)

ShellcodeFluctuation PoC ported to Nim

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.