
HandleKatz
PIC-based Lsass memory dumper using cloned handles to evade detection, producing obfuscated dumps with minimal memory footprint for red team…

PIC-based Lsass memory dumper using cloned handles to evade detection, producing obfuscated dumps with minimal memory footprint for red team…

Build anti-detection Frida server from source. ~90 patches covering 16 detection vectors, weekly auto-builds with random names.


Dynamically invoke arbitrary unmanaged code

PE loader with various shellcode injection techniques

Compromising the macOS Kernel through Safari by Chaining Six Vulnerabilities

CVE-2020-15368, aka "How to exploit a vulnerable driver"

Herramienta para evadir disable_functions y open_basedir

Stealthy DLL proxying implant for Microsoft Teams that injects AES-encrypted shellcode via unhooking techniques, providing persistent backdoor access…

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

Automated DLL Sideloading Tool With EDR Evasion Capabilities


CVE-2018-10933 very simple POC

micr0shell is a Python script that dynamically generates Windows X64 PIC Null-Free reverse shell shellcode.

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

Patching ROP-encoded shellcodes into PEs

Public repository for improvements to the EXTRABACON exploit

RCE exploit for CVE-2023-3519