
sliver
Adversary Emulation Framework

Adversary Emulation Framework

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

Windows memory hacking library

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

A shellcode loader generator with support for multiple injection techniques, built for red team engagements.

Modular Windows C2 framework with a Rust teamserver, Zig implant, indirect syscalls, AMSI bypass, reflective/PoolParty injection, in-memory BOF…

Multi-module offensive security toolkit for SOCKS5 proxy chaining, port scanning, DNS enumeration, hash cracking, reverse shell generation,…

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

AV/EDR evasion via direct system calls.

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

Python 3 exploit for CVE-2019-3980. Unauthenticated RCE as SYSTEM via SolarWinds Dameware MRC smart card authentication bypass.

Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification study (CRTO).

PoCs and tools for investigation of Windows process execution techniques

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…