
KDU
Windows kernel driver utility that abuses vulnerable signed drivers (BYOVD) to bypass DSE, load unsigned drivers, hijack protected processes, and…

Windows kernel driver utility that abuses vulnerable signed drivers (BYOVD) to bypass DSE, load unsigned drivers, hijack protected processes, and…

Threadless Process Injection using remote function hooking.

Protect process by shellcode

A shellcode function to encrypt a running process image when sleeping.

NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

Windows x64 handcrafted token stealing kernel-mode shellcode

PoCs and tools for investigation of Windows process execution techniques

A dynamic unpacking tool


PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Hijacks code execution via overwriting Control Flow Guard pointers in combase.dll

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

This is a hypothetical demonstration of the process involved in exploiting LogoFail, it theoretically includes the necessary steps.

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

WNF Code Execution Library Using C#

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

Script to exploit CVE-2023-38035

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…