
r77-rootkit
Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

AV/EDR evasion via direct system calls.


AV/EDR evasion via direct system calls.

Converts PE into a shellcode

EternalBlue suite remade in C/C++ which includes: MS17-010 Exploit, EternalBlue vulnerability detector, DoublePulsar detector and DoublePulsar…

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

.NET, PE, & Raw Shellcode Packer/Loader Written in Nim

Inject a shared library (i.e. arbitrary code) into a live linux process, without ptrace

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…


Dynamically invoke arbitrary unmanaged code

Various ways to execute shellcode

基于Java实现的Shellcode加载器

An Bash&Python Script For Generating Payloads that Bypasses All Antivirus so far [FUD]

C++ shellcode injection technique using XOR encryption and UUID string conversion to bypass Windows Defender, with function call obfuscation and…