
MorphAES
IDPS & SandBox & AntiVirus STEALTH KILLER. MorphAES is the world's first polymorphic shellcode engine, with metamorphic properties and capability to…

IDPS & SandBox & AntiVirus STEALTH KILLER. MorphAES is the world's first polymorphic shellcode engine, with metamorphic properties and capability to…

Go shellcode loader that combines multiple evasion techniques

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Apply a divide and conquer approach to bypass EDRs

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

Nim Library for Offensive Security Development

Execute shellcode files with rundll32

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…


C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…

🌒 Shell command obfuscation to avoid detection systems

Indirect syscalls + DInvoke made simple.

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…