
sliver
Adversary Emulation Framework

Adversary Emulation Framework

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

Threadless Process Injection using remote function hooking.

C# Reflective loader for unmanaged binaries.

MD5-Monomorphic Shellcode Packer - all payloads have the same MD5 hash

Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

Shellcode injection technique. Given as C++ header, standalone Rust program or library.

Malicious DOCX generator exploiting CVE-2021-40444 (Microsoft Office Word RCE) with CAB-based DLL side-loading and CAB-less RAR/WSF attack chains for…

Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.