
Ivy
Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing…

A buffer overflow vulnerability in the control protocol of Flexense SyncBreeze Enterprise v10.4.18 allows remote attackers to execute arbitrary code…

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of…

SharpSploit is a .NET post-exploitation library written in C#

Work in Progress. RAT written in C++ using wxWidgets

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

My experiments in weaponizing Nim (https://nim-lang.org/)

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Payload Generation Framework

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

A workshop about Malware Development

Hide your Powershell script in plain sight. Bypass all Powershell security features

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

PIC-based Lsass memory dumper using cloned handles to evade detection, producing obfuscated dumps with minimal memory footprint for red team…

MSFvenom Payload Creator (MSFPC)

Reflective PE packer.

EXOCET - AV-evading, undetectable, payload delivery tool

A fully implemented kernel exploit for the PS4 on 5.05FW