
ThreadlessInject
Threadless Process Injection using remote function hooking.

Threadless Process Injection using remote function hooking.

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

Windows x64 handcrafted token stealing kernel-mode shellcode

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

Various ways to execute shellcode

ShellcodeFluctuation PoC ported to Nim

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

A simple ptrace-less shared library injector for x64 Linux

Simple dotnet Native AOT app that uses AsmResolver to convert shellcode to PE

Hijacks code execution via overwriting Control Flow Guard pointers in combase.dll

Modern PIC implant for Windows (64 & 32 bit)

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…

PoC for popping a system shell against the LnvMSRIO.sys driver

A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.



bin2shell is very small utils for extract shell code from the binary file