
sliver
Adversary Emulation Framework

Adversary Emulation Framework

Google Chrome CVE-2026-6307 PoC

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Generates JavaScript payloads to exploit CVE-2024-28397 Js2Py sandbox escape, enabling remote command execution and reverse shells via Python…

Linux Shared Library to Shellcode Loader

The Havoc Framework

A helper utility for creating shellcodes. Cleans MASM file generated by MSVC, gives refactoring hints.

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

Foxit PDF Reader Remote Code Execution Exploit

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs

CVE-2023-2255 Libre Office

Native syscall shellcode injector using HellsGate/HalosGate/TartarusGate for undetectable execution, with external shellcode loading and EDR evasion…

Go shellcode loader that combines multiple evasion techniques

A simple PoC to invoke an encrypted shellcode by using an hidden call

Shellcode loader demonstrating multiple execution techniques including direct syscalls, IAT evasion, encrypted payloads, PPID spoofing, and code…

Kage is Graphical User Interface for Metasploit Meterpreter and Session Handler

AV/EDR evasion via direct system calls.

WIP shellcode loader in nim with EDR evasion techniques