
PoolParty
A set of fully-undetectable process injection techniques abusing Windows Thread Pools

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners…

A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.

Venom C2 is a dependency‑free Python3 Command & Control framework for redteam persistence

Obfusk8: lightweight Obfuscation library based on C++17 / Header Only for windows binaries

CVE-2020-15368, aka "How to exploit a vulnerable driver"

A fully featured Windows backdoor that uses Gmail as a C&C server

Threadless Process Injection using remote function hooking.

RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

MD5-Monomorphic Shellcode Packer - all payloads have the same MD5 hash

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

Cooolis-ms是一个包含了Metasploit Payload Loader、Cobalt Strike External C2 Loader、Reflective DLL injection的代码执行工具,它的定位在于能够在静态查杀上规避一些我们将要执行且含有特征的代码,帮助红队人员更方便快…

Multiplatform reverse shell generator

An Bash&Python Script For Generating Payloads that Bypasses All Antivirus so far [FUD]

C++ shellcode injection technique using XOR encryption and UUID string conversion to bypass Windows Defender, with function call obfuscation and…