
Dirty-Vanity
Windows code injection PoC that abuses the fork API to execute ntdll-based shellcode in a forked process and bypass EDRs.

Windows code injection PoC that abuses the fork API to execute ntdll-based shellcode in a forked process and bypass EDRs.

Excel 4.0 (XLM) Macro Generator for injecting DLLs and EXEs into memory.

Cross-platform TCP reverse shell with TLS encryption, certificate pinning, shellcode injection, and meterpreter staging for red team operations.

Stealthy, code-golfed PHP webshell family with authentication support and undetectable payload delivery for remote command execution via HTTP.

Simple & Powerful PowerShell Script Obfuscator

Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)

Ready-to-use shellcode execution examples in C, C#, and MATLAB, covering different process-loading techniques for offensive security research and…

Compromising the macOS Kernel through Safari by Chaining Six Vulnerabilities

PE loader with various shellcode injection techniques

Cobalt Strike BOF for spawning sacrificial processes with Arbitrary Code Guard, BlockDll, and PPID spoofing to inject shellcode and execute payloads…

Exploit for CVE-2017-11882 (Microsoft Office Equation Editor buffer overflow) supporting shellcode injection and command execution with payloads up…

A fully featured Windows backdoor that uses Gmail as a C&C server

SMBGhost (CVE-2020-0796) Automate Exploitation and Detection

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

A stealthy Python based Windows backdoor that uses Github as a command and control server

From XSS to RCE 2.75 - Black Hat Europe Arsenal 2017 + Extras

Windows x64 handcrafted token stealing kernel-mode shellcode

Automated DLL Sideloading Tool With EDR Evasion Capabilities