
SleepyCrypt
A shellcode function to encrypt a running process image when sleeping.

A shellcode function to encrypt a running process image when sleeping.

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

Nim Library for Offensive Security Development

Apply a divide and conquer approach to bypass EDRs

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

Shellcode Loader with Indirect Dynamic syscall Implementation , shellcode in MAC format, API resolving from PEB, Syscall calll and syscall…

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level


Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Execute shellcode files with rundll32

Indirect syscalls + DInvoke made simple.

Dynamically invoke arbitrary unmanaged code

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…

Dynamic shellcode loader with sophisticated evasion capabilities