
Fritter
Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

C-based exploit for CVE-2026-31431 in the Linux Kernel Crypto API, targeting aarch64 and amd64 architectures with shellcode generation and ancillary…

Exploit for CVE-2022-42475, a pre-auth RCE in FortiOS SSL VPN. Supports validation, benign verification, and full exploitation with connect-back…

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

Apply a divide and conquer approach to bypass EDRs

NTP-based backdoor for hardened networks, delivering and executing arbitrary shellcode via spoofed NTP traffic with optional persistence as a Windows…

Linux ELF x32/x64 ASLR DEP/NX bypass exploit with stack-spraying

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

CVE-2015-7547 initial research.

Documentation and proof of concept code for CVE-2022-24125 and CVE-2022-24126.

WIP shellcode loader in nim with EDR evasion techniques

Serv-U-FTP CVE-2021-35211 exploit

Manual exploit for Firefox RCE CVE-2016-9079 with customizable shellcode, served via HTTP for remote code execution on vulnerable Windows systems.
