
Project-Onyx
Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

Apply a divide and conquer approach to bypass EDRs

C-shellcode to hex converter, handy tool for paste & execute shellcodes in IDA PRO, gdb, windbg, radare2, ollydbg, x64dbg, immunity debugger & 010…

A Windows Remote Administration Tool in Visual Basic with UNC paths

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

A tool to abuse Exchange services

A repository of Windows Shellcode runners and supporting utilities. The applications load and execute Shellcode using various API calls or techniques.

evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)

Killer is a super simple tool designed to bypass AV/EDR security tools using various evasive techniques and used by Patchwork group.

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

MeterSSH is a way to take shellcode, inject it into memory then tunnel whatever port you want to over SSH to mask any type of communications as a…

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

PIC-based Lsass memory dumper using cloned handles to evade detection, producing obfuscated dumps with minimal memory footprint for red team…

:cherry_blossom: Interactive shellcoding environment to easily craft shellcodes

A simple shell code encryptor/decryptor/executor to bypass anti virus.

A Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions

A small, null-free Windows shellcode that executes calc.exe (x86/x64, all OS/SPs)