
CVE-2021-40444
Malicious DOCX generator exploiting CVE-2021-40444 (Microsoft Office Word RCE) with CAB-based DLL side-loading and CAB-less RAR/WSF attack chains for…

Malicious DOCX generator exploiting CVE-2021-40444 (Microsoft Office Word RCE) with CAB-based DLL side-loading and CAB-less RAR/WSF attack chains for…

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

Adversary Emulation Framework

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

MD5-Monomorphic Shellcode Packer - all payloads have the same MD5 hash

C# Reflective loader for unmanaged binaries.

Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.

Threadless Process Injection using remote function hooking.

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.

Shellcode injection technique. Given as C++ header, standalone Rust program or library.