
TinyLoad
Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Bypassing Linux Executable Space Protection using 20+ years old tools (CVE-2022-25265).

CVE-2019-9729. Transferred from https://github.com/DoubleLabyrinth/SdoKeyCrypt-sys-local-privilege-elevation

CVE-2009-0182 VUPlayer2.49_LocalBufferOverflow

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

AV/EDR evasion via direct system calls.

Hide your Powershell script in plain sight. Bypass all Powershell security features

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions


P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

DropEngine provides a malleable framework for creating shellcode runners, allowing operators to choose from a selection of components and combine…

Shellcode injection technique. Given as C++ header, standalone Rust program or library.

A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.

Obfusk8: lightweight Obfuscation library based on C++17 / Header Only for windows binaries

Implementation of an export address table protection mitigation, like Export Address Filtering (EAF)

Windows memory hacking library

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

.NET, PE, & Raw Shellcode Packer/Loader Written in Nim