
ThreadlessInject
Threadless Process Injection using remote function hooking.

Threadless Process Injection using remote function hooking.

C# Reflective loader for unmanaged binaries.

UNIX-like reverse engineering framework and command-line toolset.

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

Simulates the Windows PE loader to identify DLL hijacking vulnerabilities, generates weaponized DLLs with shellcode payloads, and detects UAC…

A standalone DLL that exports databases in cleartext once injected in the KeePass process.

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

bespoke tooling for offensive security's Windows Usermode Exploit Dev course (OSED)

Practical Windows malware development course: API hashing, DLL sideloading, shellcode execution, PE manipulation, payload hosting, and delivery labs.

Palo Alto - CVE-2026-0300 exploit

Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.

Windows User-Mode Shellcode Development Framework (WUMSDF)

bin2shell is very small utils for extract shell code from the binary file

Previously-0day exploit from the Hacking Team leak, written by Eugene Ching/Qavar.


Python exploit for Serv-U SSH vulnerability (CVE-2021-35211) with multiple payload modes: stage, exec, and download-execute, enabling shellcode…

MCP Server for Metasploit

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection