
ThreadlessInject
Threadless Process Injection using remote function hooking.

Threadless Process Injection using remote function hooking.

C# Reflective loader for unmanaged binaries.

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

PoCs and tools for investigation of Windows process execution techniques

ShellcodeFluctuation PoC ported to Nim

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

A simple ptrace-less shared library injector for x64 Linux

Apply a divide and conquer approach to bypass EDRs

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.


Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

Modern PIC implant for Windows (64 & 32 bit)