
baron-samedit
This repository contains a Proof-of-Concept (PoC) exploit for the Baron Samedit vulnerability (CVE-2021-3156). The exploit demonstrates privilege…

This repository contains a Proof-of-Concept (PoC) exploit for the Baron Samedit vulnerability (CVE-2021-3156). The exploit demonstrates privilege…

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode in…

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode in…

A fully featured backdoor that uses Twitter as a C&C server

Hershell is a simple TCP reverse shell written in Go.

A fully featured Windows backdoor that uses Gmail as a C&C server

Threadless Process Injection using remote function hooking.

Build anti-detection Frida server from source. ~90 patches covering 16 detection vectors, weekly auto-builds with random names.

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

LittleCorporal: A C# Automated Maldoc Generator

Python AV Evasion Tools

Linux ELF x32/x64 ASLR DEP/NX bypass exploit with stack-spraying

WIP shellcode loader in nim with EDR evasion techniques

A Libemu Cython wrapper

takes shellcode bad-bytes and banishes them, returning cleaned shellcode with preserved functionalities

A high-fidelity x86_64 polymorphic mutation engine focused on instruction-level fragmentation and context preservation.

Cobalt Strike Beacon Object File implementing CVE-2020-0796 SMBGhost local privilege escalation with dual weaponization paths for token theft and…

Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification study (CRTO).