
sliver
Adversary Emulation Framework

Adversary Emulation Framework

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

DropEngine provides a malleable framework for creating shellcode runners, allowing operators to choose from a selection of components and combine…

Shellcode loader demonstrating multiple execution techniques including direct syscalls, IAT evasion, encrypted payloads, PPID spoofing, and code…

The Havoc Framework

A helper utility for creating shellcodes. Cleans MASM file generated by MSVC, gives refactoring hints.

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Kage is Graphical User Interface for Metasploit Meterpreter and Session Handler

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs

Go shellcode loader that combines multiple evasion techniques

Native syscall shellcode injector using HellsGate/HalosGate/TartarusGate for undetectable execution, with external shellcode loading and EDR evasion…

Google Chrome CVE-2026-6307 PoC

AV/EDR evasion via direct system calls.

WIP shellcode loader in nim with EDR evasion techniques

Previously-0day exploit from the Hacking Team leak, written by Eugene Ching/Qavar.

A simple PoC to invoke an encrypted shellcode by using an hidden call

Deploy payloads to *Nix systems en masse