
ShellcodeFluctuation
An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

MD5-Monomorphic Shellcode Packer - all payloads have the same MD5 hash

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

C# Reflective loader for unmanaged binaries.

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Apply a divide and conquer approach to bypass EDRs

A simple ptrace-less shared library injector for x64 Linux

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…


Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

Modern PIC implant for Windows (64 & 32 bit)

ShellcodeFluctuation PoC ported to Nim

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Reverse Shell Detection with Machine Learning