
RunPE
C# Reflective loader for unmanaged binaries.

C# Reflective loader for unmanaged binaries.

Multi-architecture assembler framework that converts assembly source into machine code for Arm, x86, MIPS, PowerPC, RISC-V, and more, with a…

CVE-2026-8452 PreAuth RCE

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Simulates the Windows PE loader to identify DLL hijacking vulnerabilities, generates weaponized DLLs with shellcode payloads, and detects UAC…

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

Practical Windows malware development course: API hashing, DLL sideloading, shellcode execution, PE manipulation, payload hosting, and delivery labs.

Palo Alto - CVE-2026-0300 exploit

Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.

Windows User-Mode Shellcode Development Framework (WUMSDF)

Decrypted content of eqgrp-auction-file.tar.xz


## 在kali中自动化生成cve-2017-8570的恶意ppsx文件和配置msf监听

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

Python exploit for Webmin CVE-2022-0824 with dual-mode support: direct command execution and reverse shell. Features multiple payload types,…

Generates JavaScript payloads to exploit CVE-2024-28397 Js2Py sandbox escape, enabling remote command execution and reverse shells via Python…

Suite for reverse shell handling geared toward working within the native shell

Microsoft-Office-Word-MSHTML-Remote-Code-Execution-Exploit