
sgn
Polymorphic binary encoder for offensive security payloads. Encodes shellcode with LFSR-based feedback loop, garbage instruction injection, and…

Polymorphic binary encoder for offensive security payloads. Encodes shellcode with LFSR-based feedback loop, garbage instruction injection, and…

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Dynamically invoke arbitrary unmanaged code

🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

Generates weaponized JPEG files exploiting CVE-2025-50165 (Windows Graphics RCE) with custom x64 shellcode, heap spray, ROP chain, and AV/EDR evasion…

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…

Dynamic shellcode loader with sophisticated evasion capabilities

Converts PE into a shellcode

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

Indirect syscalls + DInvoke made simple.

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…


Execute shellcode files with rundll32

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

SysWhispers on Steroids - AV/EDR evasion via direct system calls.