
NimSyscallPacker
Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

SMBGhost (CVE-2020-0796) Automate Exploitation and Detection

Fileless lateral movement tool using WMI Event Subscriptions to execute .NET assemblies in memory, with shellcode injection via named pipes for…

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Public repository for improvements to the EXTRABACON exploit

Intel 64/Windows low-level experiments

Deploy payloads to *Nix systems en masse

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

A simple PoC to invoke an encrypted shellcode by using an hidden call

Fileless x64 Assembly C2 framework with dual-channel ICMP/DNS protocol pivoting, direct syscall execution, and ptrace-based process injection for…

Crystal Palace Evasion kit for Sliver

A shellcode loader generator with support for multiple injection techniques, built for red team engagements.


Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Use YARA rules on Time Travel Debugging traces

Yet Another PHP Shell - The most complete PHP reverse shell