
Lastenzug
Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Various ways to execute shellcode

A third-party Gopher Assassin for the Havoc Framework.

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

Windows User-Mode Shellcode Development Framework (WUMSDF)

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

A fully implemented kernel exploit for the PS4 on 5.05FW

exploitdb // The official Exploit-Database repository

WORK IN PROGRESS. RAT written in C++ using Win32 API

Work in Progress. RAT written in C++ using wxWidgets


Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

End-to-end exploitation lab for CVE-2025-5548 (FreeFloat FTP Server stack buffer overflow). Includes static analysis with IDA/Ghidra, binary fuzzing,…