
libpeconv
Custom PE loading and manipulation library for manual mapping, IAT hooking, memory dumping, and rebuilding imports for malware analysis and reverse…

Custom PE loading and manipulation library for manual mapping, IAT hooking, memory dumping, and rebuilding imports for malware analysis and reverse…

Collection of radare2 scripts for malware analysis: carve binaries from memory dumps, patch PE headers, and decode hashed function imports in…

PIC-based Lsass memory dumper using cloned handles to evade detection, producing obfuscated dumps with minimal memory footprint for red team…

BOF to run PE in Cobalt Strike Beacon without console creation

Windows LPE exploit for CVE-2021-40449, a use-after-free in win32kfull!GreResetDCInternal, leveraging token leaking, kernel gadget abuse, and…

Copy Fail - CVE-2026-31431

Trigger-only for CVE-2021-29627

Proof-of-concept exploit for CVE-2024-1065, demonstrating page cache exploitation via a use-after-free in the ARM Mali GPU kernel driver to achieve…

Linux kernel local privilege escalation exploit for CVE-2017-16994, leveraging null pointer dereference and mmap_min_addr bypass to achieve root…

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.


A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

AV/EDR evasion via direct system calls.

Converts PE into a shellcode

🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

AV/EDR evasion via direct system calls.