
donut
Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

A tool to abuse Exchange services

Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with…

A repository of Windows Shellcode runners and supporting utilities. The applications load and execute Shellcode using various API calls or techniques.

Offensive Software Exploitation Course

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Payload Generation Framework


Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors

Pack shellcode and PE executables into evasive payloads with anti-debug, unhooking, syscall, and memory fluctuation techniques for red-team…

AV/EDR evasion via direct system calls.

SSH-based reverse shell management tool with native SCP/SFTP support, multiple transport protocols, Windows DLL generation, and fileless execution…

Converts PE into a shellcode


🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

AV/EDR evasion via direct system calls.

A fully featured backdoor that uses Twitter as a C&C server