
GoPurple
Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Antivirus evasion project

A fully featured backdoor that uses Twitter as a C&C server

Polymorphic encryptor that transforms shellcode, PE, and COFF files into obfuscated, position-independent payloads with RC4 and random block cipher…

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

A fully implemented kernel exploit for the PS4 on 5.05FW

Hershell is a simple TCP reverse shell written in Go.

Various ways to execute shellcode

A fully featured Windows backdoor that uses Gmail as a C&C server

An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

exploitdb // The official Exploit-Database repository

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

Assist reverse tcp shells in post-exploration tasks


Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.