
hackEmbedded
This tool is used for encrypt backdoor,shellcode,socks5 proxy generation,Information retrieval and POC arrangement for various architecture devices

This tool is used for encrypt backdoor,shellcode,socks5 proxy generation,Information retrieval and POC arrangement for various architecture devices

Stealthy DLL proxying implant for Microsoft Teams that injects AES-encrypted shellcode via unhooking techniques, providing persistent backdoor access…

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

poc for CVE-2025-24252 & CVE-2025-24132

PoC Thread Execution Hijacking for Win32 Code Injection

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

indirect syscalls for AV/EDR evasion in Go assembly

An open-source, C#-based remote administration tool (RAT), enabling complete control of a remote Windows machine, designed for legitimate remote…

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.

Modern PIC implant for Windows (64 & 32 bit)

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal Palace.

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

Get your data from the resource section manually, with no need for windows apis


Nim-based encryption tool for obfuscating shellcode and payloads for evading Windows Defender.