
TangledWinExec
PoCs and tools for investigation of Windows process execution techniques

PoCs and tools for investigation of Windows process execution techniques

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment

Threadless Process Injection using remote function hooking.

Suite for reverse shell handling geared toward working within the native shell

A standalone DLL that exports databases in cleartext once injected in the KeePass process.

Windows memory hacking library

Native syscall shellcode injector using HellsGate/HalosGate/TartarusGate for undetectable execution, with external shellcode loading and EDR evasion…