
RpcProxyInvoke
Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

Crystal Palace Evasion kit for Sliver

A simple PoC to invoke an encrypted shellcode by using an hidden call

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…

Use YARA rules on Time Travel Debugging traces

🌒 Shell command obfuscation to avoid detection systems

A shellcode loader generator with support for multiple injection techniques, built for red team engagements.

Cobalt Strike UDRL that performs advanced module stomping using VEH to intercept calls, unmap modules during sleep, and remap fresh modules to evade…

Rust-based Windows PE manual loader that maps and executes x86/x64 executables from memory, demonstrating internal loader behavior and PE structure…

Yet Another PHP Shell - The most complete PHP reverse shell



Indirect syscalls + DInvoke made simple.

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal Palace.

Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification study (CRTO).
