
unicorn
Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Convert shellcode into :sparkles: different :sparkles: formats!

Killer is a super simple tool designed to bypass AV/EDR security tools using various evasive techniques and used by Patchwork group.

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

Hide your Powershell script in plain sight. Bypass all Powershell security features

Apply a divide and conquer approach to bypass EDRs

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

AV/EDR evasion via direct system calls.

AV/EDR evasion via direct system calls.

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

Go shellcode loader that combines multiple evasion techniques

CVE-2018-10933 very simple POC

🌒 Shell command obfuscation to avoid detection systems

CVE-2020-0022 vulnerability exploitation on Bouygues BBox Miami (Android TV 8.0 - ARM32 Cortex A9)