
BOF_ExecuteAssembly
Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

Nim Library for Offensive Security Development

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

Execute shellcode files with rundll32

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

🌒 Shell command obfuscation to avoid detection systems

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…

Indirect syscalls + DInvoke made simple.

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…

Generates weaponized JPEG files exploiting CVE-2025-50165 (Windows Graphics RCE) with custom x64 shellcode, heap spray, ROP chain, and AV/EDR evasion…

Black Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled DSE while maintaining its full functionality.

Shellcode injection technique. Given as C++ header, standalone Rust program or library.

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

PoCs and tools for investigation of Windows process execution techniques

Python-based forward shell tool that creates a TTY-like interactive shell over HTTP using named pipes, enabling command execution on firewalled…