
wnfexec
WNF Code Execution Library Using C#

WNF Code Execution Library Using C#

Hijacks code execution via overwriting Control Flow Guard pointers in combase.dll

PoCs and tools for investigation of Windows process execution techniques

Pure Rust x86 hardware emulator and Windows process simulator for malware analysis, shellcode emulation, and payload unpacking. Supports 32/64-bit PE…

Exploit POC for the bug CVE-2019-8781, found by @LinusHenze

ScareCrow - Payload creation framework designed around EDR bypass.

Inject .NET assemblies into an existing process

Protect process by shellcode

A shellcode function to encrypt a running process image when sleeping.

Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks by spawning…

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

Windows memory hacking library

Remote root exploit for the SAMBA CVE-2017-7494 vulnerability

A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.

BOF to run PE in Cobalt Strike Beacon without console creation

Nim-based process hollowing loader for PE executables with configurable injection methods, direct/indirect syscalls, anti-debug, payload encryption,…

A variation of ProcessOverwriting to execute shellcode on an executable's section

NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection