
sliver
Adversary Emulation Framework

Adversary Emulation Framework

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

Reverse Shell Detection with Machine Learning

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

PoCs and tools for investigation of Windows process execution techniques

Evaluation framework for studying LLM agents that automatically generate working exploits from vulnerability reports, bypassing modern security…

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.

Modern PIC implant for Windows (64 & 32 bit)


This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

Threadless Process Injection using remote function hooking.


A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver