
ThreadlessInject
Threadless Process Injection using remote function hooking.

Threadless Process Injection using remote function hooking.

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

Simulates the Windows PE loader to identify DLL hijacking vulnerabilities, generates weaponized DLLs with shellcode payloads, and detects UAC…

Windows code injection PoC that abuses the fork API to execute ntdll-based shellcode in a forked process and bypass EDRs.

Converts PE files (EXE/DLL) into position-independent shellcode with optional LZNT1 compression and obfuscation, supporting x86/x64, .NET, and Go…

Extracts executable shellcode from compiled binary files and outputs escaped hexadecimal byte strings (e.g., \x45\x6e) for exploit development and…

Previously-0day exploit from the Hacking Team leak, written by Eugene Ching/Qavar.

Generate Windows 11 x64 reverse TCP shellcode with PIC technique, supporting C, Python, C#, and PowerShell output formats for red team engagements.

Python script that wraps nasm/objdump to quickly generate shellcode bytes from assembly instructions or compiled ELF binaries, supporting multiple…

Automated exploit generator for CVE-2017-8570 that creates malicious PPSX files and configures Metasploit listeners for remote shell access.

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

Python exploit for Webmin CVE-2022-0824 with dual-mode support: direct command execution and reverse shell. Features multiple payload types,…

Generates JavaScript payloads to exploit CVE-2024-28397 Js2Py sandbox escape, enabling remote command execution and reverse shells via Python…

Malicious DOCX generator exploiting CVE-2021-40444 (Microsoft Office Word RCE) with CAB-based DLL side-loading and CAB-less RAR/WSF attack chains for…

Multi-CVE WebLogic deserialization exploit builder with support for process builder, serialized, and URL-based payloads, enabling remote command…

a exp for cve-2018-9948/9958 , current shellcode called win-calc

Custom CAB template generator for CVE-2021-40444, crafting malicious cabinet archives to exploit Windows MSHTML remote code execution via crafted…