
anamnesis-release
Evaluation framework for studying LLM agents that automatically generate working exploits from vulnerability reports, bypassing modern security…

Evaluation framework for studying LLM agents that automatically generate working exploits from vulnerability reports, bypassing modern security…

An Bash&Python Script For Generating Payloads that Bypasses All Antivirus so far [FUD]

Stealthy DLL proxying implant for Microsoft Teams that injects AES-encrypted shellcode via unhooking techniques, providing persistent backdoor access…

C# tool that generates malicious VBA macros with shellcode injection, VBA purging, and sandbox detection for red team operations.

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

micr0shell is a Python script that dynamically generates Windows X64 PIC Null-Free reverse shell shellcode.

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

Go shellcode loader that combines multiple evasion techniques

Java-based exploit for CVE-2022-26134 that injects a Godzilla webshell into Confluence servers, enabling remote code execution with password and key…

Go package that aids in binary analysis and exploitation

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

Python-based forward shell tool that creates a TTY-like interactive shell over HTTP using named pipes, enabling command execution on firewalled…

A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.

A collection of various and sundry code snippets that leverage .NET dynamic tradecraft

NØW is a word-based shellcode encoding and obfuscation tool that transforms raw shellcode bytes into natural-looking English prose.

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.

A PoC UDRL for Cobalt Strike built with Crystal Palace that combines Raphael Mudge's page streaming technique with a modular call gate (Draugr)