
KDU
Windows kernel driver utility that abuses vulnerable signed drivers (BYOVD) to bypass DSE, load unsigned drivers, hijack protected processes, and…

Windows kernel driver utility that abuses vulnerable signed drivers (BYOVD) to bypass DSE, load unsigned drivers, hijack protected processes, and…

A PoC on how to use a Compute Shader as Payload

A concept of using a ROP chain paired with a WRMSR primitive to call kernel functions and map unsigned drivers through BYOVD (AmdTools64.sys)

C# Reflective loader for unmanaged binaries.

A QoL tool to obfuscate shellcode. In the future will be able to chain encoding/encryption/compression methods.

A dynamic unpacking tool

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Swiss Army Knife for payload encryption, obfuscation, and conversion to byte arrays – all in a single command (14 output formats supported)! ☢️

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.

This is a custom ASCII AND/SUB Encoder developed during my preparation for the legacy OSCE/CTP course

Extending of metasploit-framework

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support


Universal stack-based buffer overfow exploitation tool

pinky - The PHP mini RAT (Remote Administration Tool)

A Windows Remote Administration Tool in Visual Basic with UNC paths

Herramienta para evadir disable_functions y open_basedir

PoC code for vulnerability in webmod v0.48. Originally written in 2007, assigned CVE-2007-1260.