
aether
Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

PowerSploit - A PowerShell Post-Exploitation Framework

A dynamic unpacking tool

Multi-purpose proof-of-concept tool based on CPU-Z CVE-2017-15303

Utilizing TLS callbacks to execute a payload without spawning any threads in a remote process

Windows x64 handcrafted token stealing kernel-mode shellcode

Python-based exploit for CVE-2021-21086 in Adobe Acrobat Reader DC, generating malicious PDFs with shellcode execution via crafted font charstrings.

A memory-based evasion technique which makes shellcode invisible from process start to end.

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

CVE-2024-24576 Proof of Concept

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.

Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment

Rusty Injection - Shellcode Reflective DLL Injection (sRDI) in Rust (Codename: Venom)

Script to exploit CVE-2023-38035

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…


Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…