
Project-Onyx
Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

exploitdb // The official Exploit-Database repository

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

Windows User-Mode Shellcode Development Framework (WUMSDF)

End-to-end exploitation lab for CVE-2025-5548 (FreeFloat FTP Server stack buffer overflow). Includes static analysis with IDA/Ghidra, binary fuzzing,…

Python exploit for vsFTPd 2.3.4 backdoor (CVE-2011-2523) that triggers a hidden shell on port 6200 via a crafted username, enabling remote command…

Polymorphic encryptor that transforms shellcode, PE, and COFF files into obfuscated, position-independent payloads with RC4 and random block cipher…

A PoC project for embedding shellcode to Hint/Name Table

Buffer overflow in FreeFloat FTP Server 1.0

Detection reverse shell and kill it before trying shell.

Assist reverse tcp shells in post-exploration tasks

Builds a shell.so reverse shell payload for CVE-2025-1974 (IngressNightmare) using Alpine Linux in Docker, with hardcoded IP and port configuration.

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

Practical Windows malware development course: API hashing, DLL sideloading, shellcode execution, PE manipulation, payload hosting, and delivery labs.

Antivirus evasion project

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

Various ways to execute shellcode