
NullGate
Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.


Stealthy DLL proxying implant for Microsoft Teams that injects AES-encrypted shellcode via unhooking techniques, providing persistent backdoor access…

Forth-based compiler deployed as position-independent x86_64 shellcode, providing a remote code execution agent with interactive REPL over TCP, HTTP,…

A fully featured Windows backdoor that uses Gmail as a C&C server

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

A fully featured backdoor that uses Twitter as a C&C server

Polymorphic encryptor that transforms shellcode, PE, and COFF files into obfuscated, position-independent payloads with RC4 and random block cipher…

A PoC project for embedding shellcode to Hint/Name Table

Python exploit for vsFTPd 2.3.4 backdoor (CVE-2011-2523) that triggers a hidden shell on port 6200 via a crafted username, enabling remote command…

Antivirus evasion project

C# Reflective loader for unmanaged binaries.

An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits

Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

A fully implemented kernel exploit for the PS4 on 5.05FW