
ShellCodeEmulator
Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment

Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment

A memory-based evasion technique which makes shellcode invisible from process start to end.

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

PoCs and tools for investigation of Windows process execution techniques

A shellcode function to encrypt a running process image when sleeping.

My experiments in weaponizing Nim (https://nim-lang.org/)

Threadless Process Injection using remote function hooking.

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Windows memory hacking library

NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

Pure Rust x86 hardware emulator and Windows process simulator for malware analysis, shellcode emulation, and payload unpacking. Supports 32/64-bit PE…

Native syscall shellcode injector using HellsGate/HalosGate/TartarusGate for undetectable execution, with external shellcode loading and EDR evasion…

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

PowerSploit - A PowerShell Post-Exploitation Framework

Windows x64 handcrafted token stealing kernel-mode shellcode

RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.