
asminject
Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Nim-based process hollowing loader for PE executables with configurable injection methods, direct/indirect syscalls, anti-debug, payload encryption,…

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…

This is a hypothetical demonstration of the process involved in exploiting LogoFail, it theoretically includes the necessary steps.

Protect process by shellcode

Windows kernel driver utility that abuses vulnerable signed drivers (BYOVD) to bypass DSE, load unsigned drivers, hijack protected processes, and…

Windows memory hacking library

My experiments in weaponizing Nim (https://nim-lang.org/)

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.

Windows x64 handcrafted token stealing kernel-mode shellcode

Native syscall shellcode injector using HellsGate/HalosGate/TartarusGate for undetectable execution, with external shellcode loading and EDR evasion…

Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.

BOF to run PE in Cobalt Strike Beacon without console creation

WNF Code Execution Library Using C#
