
SleepyCrypt
A shellcode function to encrypt a running process image when sleeping.

A shellcode function to encrypt a running process image when sleeping.

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

PoCs and tools for investigation of Windows process execution techniques

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

Nim Library for Offensive Security Development

A third-party Gopher Assassin for the Havoc Framework.

Apply a divide and conquer approach to bypass EDRs

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

Shellcode Loader with Indirect Dynamic syscall Implementation , shellcode in MAC format, API resolving from PEB, Syscall calll and syscall…

This repo contains : simple shellcode Loader , Encoders (base64 - custom - UUID - IPv4 - MAC), Encryptors (AES), Fileless Loader (Winhttp, socket)

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

Use YARA rules on Time Travel Debugging traces


Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Execute shellcode files with rundll32

Indirect syscalls + DInvoke made simple.