
MSRMapper
Manual kernel driver mapper for Windows x64 that abuses CVE-2025-8061 in Lenovo's LnvMSRIO.sys to perform a BYOVD attack, mapping PE64 drivers into…

Manual kernel driver mapper for Windows x64 that abuses CVE-2025-8061 in Lenovo's LnvMSRIO.sys to perform a BYOVD attack, mapping PE64 drivers into…

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

CVE-2024-6387 POC (Currently being edited)

SHAREM is a shellcode analysis framework, capable of emulating more than 45,000 WinAPIs and virutally all Windows syscalls. It also contains its own…

Linux Shared Library to Shellcode Loader

A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.

A workshop about Malware Development

exploitdb-bin-sploits // Exploit-Database's binary exploits (what was located in the /sploits directory)

SambaCry (CVE-2017-7494) exploit for Samba | bind shell without Metasploit

PostShell - Post Exploitation Bind/Backconnect Shell

Pop shells like a master.