
c-copy-fail
C-based exploit for CVE-2026-31431 in the Linux Kernel Crypto API, targeting aarch64 and amd64 architectures with shellcode generation and ancillary…

C-based exploit for CVE-2026-31431 in the Linux Kernel Crypto API, targeting aarch64 and amd64 architectures with shellcode generation and ancillary…

C# Reflective loader for unmanaged binaries.

基于Java实现的Shellcode加载器

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

Shellcode Loader with Indirect Dynamic syscall Implementation , shellcode in MAC format, API resolving from PEB, Syscall calll and syscall…

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Use YARA rules on Time Travel Debugging traces

Dynamically invoke arbitrary unmanaged code

Practical Windows malware development course: API hashing, DLL sideloading, shellcode execution, PE manipulation, payload hosting, and delivery labs.

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…

Dynamic shellcode loader with sophisticated evasion capabilities

A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.

Windows User-Mode Shellcode Development Framework (WUMSDF)

This is a hypothetical demonstration of the process involved in exploiting LogoFail, it theoretically includes the necessary steps.

A personalized/enhanced re-creation of the Darkhotel "Double Star" APT exploit chain with a focus on Windows 8.1 and mixed with some of my own…

A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in conjunction…