
EvilVM
Forth-based compiler deployed as position-independent x86_64 shellcode, providing a remote code execution agent with interactive REPL over TCP, HTTP,…

Forth-based compiler deployed as position-independent x86_64 shellcode, providing a remote code execution agent with interactive REPL over TCP, HTTP,…

A concept of using a ROP chain paired with a WRMSR primitive to call kernel functions and map unsigned drivers through BYOVD (AmdTools64.sys)

CVE-2026-2766, but with wasm

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

Windows x64 handcrafted token stealing kernel-mode shellcode

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Various ways to execute shellcode

ShellcodeFluctuation PoC ported to Nim

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

A simple ptrace-less shared library injector for x64 Linux

A third-party Gopher Assassin for the Havoc Framework.


Hijacks code execution via overwriting Control Flow Guard pointers in combase.dll

Modern PIC implant for Windows (64 & 32 bit)

🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…