
NullGate
Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.



A fully featured Windows backdoor that uses Gmail as a C&C server

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

A fully featured backdoor that uses Twitter as a C&C server

Polymorphic encryptor that transforms shellcode, PE, and COFF files into obfuscated, position-independent payloads with RC4 and random block cipher…

A PoC project for embedding shellcode to Hint/Name Table

This exploit script is designed to simplify exploitation of the Erlang/OTP SSH vulnerability CVE-2025-32433 in the TryHackMe lab environment.

Antivirus evasion project

An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

A fully implemented kernel exploit for the PS4 on 5.05FW

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

Hershell is a simple TCP reverse shell written in Go.