
Christmas
PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Vbullettin RCE - CVE-2025-48827

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

BOF to run PE in Cobalt Strike Beacon without console creation

Buffer overflow in FreeFloat FTP Server 1.0 illustrating how a single unsafe handler can generate multiple CVE entries across different commands.

Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]

Python-based antivirus evasion tool generating undetectable executables from msfvenom payloads with advanced techniques like junkcode injection,…


Shellcode loader demonstrating multiple execution techniques including direct syscalls, IAT evasion, encrypted payloads, PPID spoofing, and code…

Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with…

SSH-based reverse shell management tool with native SCP/SFTP support, multiple transport protocols, Windows DLL generation, and fileless execution…

Nim-based process hollowing loader for PE executables with configurable injection methods, direct/indirect syscalls, anti-debug, payload encryption,…

Go shellcode loader that combines multiple evasion techniques

Cobalt Strike aggressor script for generating, formatting, and encrypting beacon shellcode with support for multiple exit methods, syscalls, and…

A shellcode loader generator with support for multiple injection techniques, built for red team engagements.