
TangledWinExec
PoCs and tools for investigation of Windows process execution techniques

PoCs and tools for investigation of Windows process execution techniques

A standalone DLL that exports databases in cleartext once injected in the KeePass process.

Suite for reverse shell handling geared toward working within the native shell

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment

Windows memory hacking library

Native syscall shellcode injector using HellsGate/HalosGate/TartarusGate for undetectable execution, with external shellcode loading and EDR evasion…