
reverse-shell
On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

Python AV Evasion Tools

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Rust-based Windows PE manual loader that maps and executes x86/x64 executables from memory, demonstrating internal loader behavior and PE structure…

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment…

7-Zip XZ Decoder Heap Buffer Overflow - Full analysis, root cause, PoC, and RCE exploitation roadmap

Windows memory hacking library

PIC-based Lsass memory dumper using cloned handles to evade detection, producing obfuscated dumps with minimal memory footprint for red team…

Public repository for improvements to the EXTRABACON exploit

Analysis for stage1 shellcode loader from hacking

CVE-2022-23093 FreeBSD Stack-Based Overflow

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

A memory-based evasion technique which makes shellcode invisible from process start to end.

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Intel 64/Windows low-level experiments

BOF to run PE in Cobalt Strike Beacon without console creation