


PostShell - Post Exploitation Bind/Backconnect Shell

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

ASPX web shell with COFF loader for executing Beacon Object Files (BOFs) on target servers via a semi-interactive Python client, designed for…

🌒 Shell command obfuscation to avoid detection systems

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

Modern PIC implant for Windows (64 & 32 bit)

Yet Another PHP Shell - The most complete PHP reverse shell


Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Get your data from the resource section manually, with no need for windows apis

Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal Palace.

A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.

CVE-2023-22527 内存马注入工具

Nim-based encryption tool for obfuscating shellcode and payloads for evading Windows Defender.

A simple tool to interact with web shells and command injection vulnerabilities