
blackpill
A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

PIC-based Lsass memory dumper using cloned handles to evade detection, producing obfuscated dumps with minimal memory footprint for red team…

Hardware Sandbox Toolkit

Python antivirus evasion tool

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

Reflective PE packer.

An Interactive Binary Patching Plugin for IDA Pro

A fully implemented kernel exploit for the PS4 on 5.05FW

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners…

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

Nano is a family of PHP web shells which are code golfed for stealth.

Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)

Pure Rust x86 hardware emulator and Windows process simulator for malware analysis, shellcode emulation, and payload unpacking. Supports 32/64-bit PE…

Various ways to execute shellcode