
TangledWinExec
PoCs and tools for investigation of Windows process execution techniques

PoCs and tools for investigation of Windows process execution techniques

Nano is a family of PHP web shells which are code golfed for stealth.

evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

SHAREM is a shellcode analysis framework, capable of emulating more than 45,000 WinAPIs and virutally all Windows syscalls. It also contains its own…

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

Armor is a simple Bash script designed to create encrypted macOS payloads capable of evading antivirus scanners.

Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)

C# implementations of shellcode injection techniques including classic injection, thread hijacking, process hollowing, and atom bombing, using…

A beacon generator using Cobalt Strike and a variety of tools.

A Nim implementation of reflective PE-Loading from memory

A POC of a new “threadless” process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote…

A technique of hiding malicious shellcode via Shannon encoding.

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

Curated collection of security tools, exploits, proof-of-concept code, shellcodes, and scripts for penetration testing and educational offensive…

Exploit Development - Weaponized Exploit and Proof of Concepts (PoC)