
OffensiveDLR
Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Killer is a super simple tool designed to bypass AV/EDR security tools using various evasive techniques and used by Patchwork group.

An Interactive Binary Patching Plugin for IDA Pro

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

A simple shell code encryptor/decryptor/executor to bypass anti virus.

SMBGhost (CVE-2020-0796) Automate Exploitation and Detection

Dynamic shellcode loader with sophisticated evasion capabilities

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

Yet Another PHP Shell - The most complete PHP reverse shell

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Nim-based encryption tool for obfuscating shellcode and payloads for evading Windows Defender.

Static analysis walkthrough of a Metasploit Windows shellcode: PowerShell payload decoding, XOR obfuscation, PEB walking, and Export Address Table…

CVE-2020-1938 / CNVD-2020-1048 Detection Tools

Proof-of-concept exploit for CVE-2025-2620, a critical stack-based buffer overflow in D-Link DAP-1620 routers enabling unauthenticated remote code…

Automatic Mass Tool for check and exploiting vulnerability in CVE-2022-4061 - JobBoardWP < 1.2.2 - Unauthenticated Arbitrary File Upload

React Server Components 远程代码执行漏洞(CVE-2025-55182)

[CVE-2024-26581] Vulnerability Checker for BGN Internal