
Blackbone
Windows memory hacking library

Windows memory hacking library

NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment

A shellcode function to encrypt a running process image when sleeping.

A memory-based evasion technique which makes shellcode invisible from process start to end.

PoCs and tools for investigation of Windows process execution techniques

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

Windows kernel driver utility that abuses vulnerable signed drivers (BYOVD) to bypass DSE, load unsigned drivers, hijack protected processes, and…

My experiments in weaponizing Nim (https://nim-lang.org/)

ScareCrow - Payload creation framework designed around EDR bypass.

Threadless Process Injection using remote function hooking.

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Pure Rust x86 hardware emulator and Windows process simulator for malware analysis, shellcode emulation, and payload unpacking. Supports 32/64-bit PE…

PowerSploit - A PowerShell Post-Exploitation Framework

Rusty Injection - Shellcode Reflective DLL Injection (sRDI) in Rust (Codename: Venom)

RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…