
Ivy
Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing…

A buffer overflow vulnerability in the control protocol of Flexense SyncBreeze Enterprise v10.4.18 allows remote attackers to execute arbitrary code…

Adversary Emulation Framework

Collection of various malicious functionality to aid in malware development


A fully featured backdoor that uses Twitter as a C&C server

A workshop about Malware Development

Shellcode loader demonstrating multiple execution techniques including direct syscalls, IAT evasion, encrypted payloads, PPID spoofing, and code…

complex webshell manager, quasi-http botnet.

A fully featured Windows backdoor that uses Gmail as a C&C server

exploitdb // The official Exploit-Database repository

Native syscall shellcode injector using HellsGate/HalosGate/TartarusGate for undetectable execution, with external shellcode loading and EDR evasion…

poc for CVE-2025-24252 & CVE-2025-24132

Executes position independent shellcode from an encrypted zip

indirect syscalls for AV/EDR evasion in Go assembly

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

Public repository for improvements to the EXTRABACON exploit

Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.