
pylibemu
A Libemu Cython wrapper

A Libemu Cython wrapper

🌒 Shell command obfuscation to avoid detection systems

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

Use YARA rules on Time Travel Debugging traces

A PoC UDRL for Cobalt Strike built with Crystal Palace that combines Raphael Mudge's page streaming technique with a modular call gate (Draugr)

CVE-2019-9729. Transferred from https://github.com/DoubleLabyrinth/SdoKeyCrypt-sys-local-privilege-elevation

ImaegMagick Code Execution (CVE-2016-3714)

Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)

Stealthy .NET assembly loading using AssemblyNative::LoadFromBuffer

Modern PIC implant for Windows (64 & 32 bit)

Yet Another PHP Shell - The most complete PHP reverse shell


MS17-010_CVE-2017-0143

Get your data from the resource section manually, with no need for windows apis

A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.

Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal Palace.

Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification study (CRTO).