
CVE-2019-18935
RCE exploit for a .NET JSON deserialization vulnerability in Telerik UI for ASP.NET AJAX.

RCE exploit for a .NET JSON deserialization vulnerability in Telerik UI for ASP.NET AJAX.

This is the main repository for metasm, a free assembler / disassembler / compiler written in ruby

A tool to generate obfuscated one liners to aid in penetration testing

Shellcode Loader with Indirect Dynamic syscall Implementation , shellcode in MAC format, API resolving from PEB, Syscall calll and syscall…

Combines AppDomain Manager injection with shellcode embedding in signed binaries to evade EDR/AV detection for red team payloads.

A QoL tool to obfuscate shellcode. In the future will be able to chain encoding/encryption/compression methods.

Fileless lateral movement tool using WMI Event Subscriptions to execute .NET assemblies in memory, with shellcode injection via named pipes for…

Utilizing TLS callbacks to execute a payload without spawning any threads in a remote process

Assist reverse tcp shells in post-exploration tasks

indirect syscalls for AV/EDR evasion in Go assembly

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

WIP shellcode loader in nim with EDR evasion techniques

Generates unique polymorphic decryption code for encrypting data, using randomly selected instructions and keys, with junk opcode generation. Written…

C-shellcode to hex converter, handy tool for paste & execute shellcodes in IDA PRO, gdb, windbg, radare2, ollydbg, x64dbg, immunity debugger & 010…

Swiss Army Knife for payload encryption, obfuscation, and conversion to byte arrays – all in a single command (14 output formats supported)! ☢️

PoC - Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (Scanner and Exploit)