
TangledWinExec
PoCs and tools for investigation of Windows process execution techniques

PoCs and tools for investigation of Windows process execution techniques

A memory-based evasion technique which makes shellcode invisible from process start to end.

Inject a shared library (i.e. arbitrary code) into a live linux process, without ptrace

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.

Threadless Process Injection using remote function hooking.

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Pure Rust x86 hardware emulator and Windows process simulator for malware analysis, shellcode emulation, and payload unpacking. Supports 32/64-bit PE…

C# implementations of shellcode injection techniques including classic injection, thread hijacking, process hollowing, and atom bombing, using…

Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks by spawning…

A POC of a new “threadless” process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote…

Inject .NET assemblies into an existing process

A shellcode function to encrypt a running process image when sleeping.

Utilizing TLS callbacks to execute a payload without spawning any threads in a remote process

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Fileless x64 Assembly C2 framework with dual-channel ICMP/DNS protocol pivoting, direct syscall execution, and ptrace-based process injection for…

Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment