
ICALL-GADGET
Exploit for redirecting control flow of a legit kernel module to your own illegitimate kernel module to evade anti-cheats stack walking

Exploit for redirecting control flow of a legit kernel module to your own illegitimate kernel module to evade anti-cheats stack walking

PS5 exploit chain for firmware 7.00-13.60 combining a WebKit JSC info leak and typedarray corruption with an aio_multi_wait UAF race for kernel…

Chained Chrome V8 renderer escape proof-of-concept exploiting four CVEs: Float64Array corruption, Wasm overwrite, popup navigation retargeting, and…

Docker-based lab and Python exploit for CVE-2013-2028, an Nginx 1.3.9 chunked-parser integer overflow, covering canary recovery, mprotect, and…

A shellcode function to encrypt a running process image when sleeping.

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

Nim Library for Offensive Security Development

Apply a divide and conquer approach to bypass EDRs

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

Shellcode Loader with Indirect Dynamic syscall Implementation , shellcode in MAC format, API resolving from PEB, Syscall calll and syscall…

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

Static analysis walkthrough of a Metasploit Windows shellcode: PowerShell payload decoding, XOR obfuscation, PEB walking, and Export Address Table…

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".


Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver