
SILVERPICK
Windows User-Mode Shellcode Development Framework (WUMSDF)

Windows User-Mode Shellcode Development Framework (WUMSDF)

Exploit for CVE-2003-0264 based on pwntools and metasploit's windows/reverse_tcp

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with…

Pack shellcode and PE executables into evasive payloads with anti-debug, unhooking, syscall, and memory fluctuation techniques for red-team…

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners…

Obfusk8: lightweight Obfuscation library based on C++17 / Header Only for windows binaries

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

Nim-based assembly packer and shellcode loader for opsec & profit

Pure Rust x86 hardware emulator and Windows process simulator for malware analysis, shellcode emulation, and payload unpacking. Supports 32/64-bit PE…

C# tool that generates malicious VBA macros with shellcode injection, VBA purging, and sandbox detection for red team operations.

Crystal Palace Evasion kit for Sliver

template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.

Rust-based User-Defined Reflective Loader for Cobalt Strike payloads. Avoids RWX memory pages for OPSEC safety. Includes an extractor tool for loader…

A Ruby framework designed to aid in the penetration testing of WordPress systems.