
donut
Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with…

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

A fully featured backdoor that uses Twitter as a C&C server

Polymorphic encryptor that transforms shellcode, PE, and COFF files into obfuscated, position-independent payloads with RC4 and random block cipher…

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

A Golang implant that uses Slack as a command and control server

A Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions

A small, null-free Windows shellcode that executes calc.exe (x86/x64, all OS/SPs)

Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks by spawning…

A POC of a new “threadless” process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote…

A fully featured Windows backdoor that uses Gmail as a C&C server

Evaluation framework for studying LLM agents that automatically generate working exploits from vulnerability reports, bypassing modern security…

An Bash&Python Script For Generating Payloads that Bypasses All Antivirus so far [FUD]

A stealthy Python based Windows backdoor that uses Github as a command and control server

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…