
Medusa
Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

Cross-platform C2 agent for Mythic with dynamic function loading, SOCKS5 proxy, file operations, shellcode injection, and macOS/Windows…

Reverse backdoor written in PowerShell and obfuscated with Python. It generates payloads for popular hacking devices like Flipper Zero and Hak5 USB…

C++ shellcode injection technique using XOR encryption and UUID string conversion to bypass Windows Defender, with function call obfuscation and…

Linux ELF x32/x64 ASLR DEP/NX bypass exploit with stack-spraying

Combines AppDomain Manager injection with shellcode embedding in signed binaries to evade EDR/AV detection for red team payloads.

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

Encoded Reverse Shell Generator With Techniques To Bypass AV's

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Native syscall shellcode injector using HellsGate/HalosGate/TartarusGate for undetectable execution, with external shellcode loading and EDR evasion…

Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment

Dynamically extracts fresh syscall stubs from ntdll.dll to evade signature-based detection, with a shellcode execution template for Nim-based…

WIP shellcode loader in nim with EDR evasion techniques

A shellcode loader generator with support for multiple injection techniques, built for red team engagements.

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

takes shellcode bad-bytes and banishes them, returning cleaned shellcode with preserved functionalities

PowerShell-based exploit for CVE-2014-4113 targeting x64 Windows systems with remote payload download and execution.

Python exploit for Webmin CVE-2022-0824 with dual-mode support: direct command execution and reverse shell. Features multiple payload types,…

Exploit for CVE-2015-8522 targeting Tivoli FastBack Server with stack-based buffer overflow, ASLR/DEP bypass, and automated reverse-shell…