
ReflectivePluginLoader
A minimal PE mapper that loads DLLs straight from memory and calls into a clean plugin interface, no LoadLibrary needed.

A minimal PE mapper that loads DLLs straight from memory and calls into a clean plugin interface, no LoadLibrary needed.

A concept of using a ROP chain paired with a WRMSR primitive to call kernel functions and map unsigned drivers through BYOVD (AmdTools64.sys)

Python exploit for MS09-050 (CVE-2009-3103) SMBv2 srv2.sys buffer overflow, with vulnerability scanner, arch auto-detection, and x86/x64 reverse…

Manual kernel driver mapper for Windows x64 that abuses CVE-2025-8061 in Lenovo's LnvMSRIO.sys to perform a BYOVD attack, mapping PE64 drivers into…

Windows x64 handcrafted token stealing kernel-mode shellcode

PoCs and tools for investigation of Windows process execution techniques

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

Apply a divide and conquer approach to bypass EDRs

A dynamic unpacking tool

Use YARA rules on Time Travel Debugging traces

Static analysis walkthrough of a Metasploit Windows shellcode: PowerShell payload decoding, XOR obfuscation, PEB walking, and Export Address Table…

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Dynamically invoke arbitrary unmanaged code

Hijacks code execution via overwriting Control Flow Guard pointers in combase.dll

Practical Windows malware development course: API hashing, DLL sideloading, shellcode execution, PE manipulation, payload hosting, and delivery labs.

Modern PIC implant for Windows (64 & 32 bit)

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…