
Project-Onyx
Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Rust Weaponization for Red Team Engagements.

SSH-based reverse shell management tool with native SCP/SFTP support, multiple transport protocols, Windows DLL generation, and fileless execution…

PIC-based Lsass memory dumper using cloned handles to evade detection, producing obfuscated dumps with minimal memory footprint for red team…

Combines AppDomain Manager injection with shellcode embedding in signed binaries to evade EDR/AV detection for red team payloads.

C# tool that generates malicious VBA macros with shellcode injection, VBA purging, and sandbox detection for red team operations.

A shellcode loader generator with support for multiple injection techniques, built for red team engagements.

Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification study (CRTO).

Repository containing exploit scripts for various CVEs, targeting web applications, binaries, and network services, suitable for penetration testing…

Adversary Emulation Framework

A workshop about Malware Development

SharpSploit is a .NET post-exploitation library written in C#

evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)

NTP-based backdoor for hardened networks, delivering and executing arbitrary shellcode via spoofed NTP traffic with optional persistence as a Windows…