
Anti_suspend
Shellcode-based process protection that prevents thread suspension, blocks debugger attach, masks hardware breakpoints, and hides threads from…

Shellcode-based process protection that prevents thread suspension, blocks debugger attach, masks hardware breakpoints, and hides threads from…

NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

ShellcodeFluctuation PoC ported to Nim

Shellcode Loader with Indirect Dynamic syscall Implementation , shellcode in MAC format, API resolving from PEB, Syscall calll and syscall…

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

Hijacks code execution via overwriting Control Flow Guard pointers in combase.dll

Get your data from the resource section manually, with no need for windows apis

bin2shell is very small utils for extract shell code from the binary file

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…


Analysis for stage1 shellcode loader from hacking

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.


PCShare是一款强大的远程控制软件,可以监视目标机器屏幕、注册表、文件系统等。


A fully featured Windows backdoor that uses email as a C&C server

WORK IN PROGRESS. RAT written in C++ using Win32 API

Build anti-detection Frida server from source. ~90 patches covering 16 detection vectors, weekly auto-builds with random names.