
TangledWinExec
PoCs and tools for investigation of Windows process execution techniques

PoCs and tools for investigation of Windows process execution techniques

Threadless Process Injection using remote function hooking.

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

A standalone DLL that exports databases in cleartext once injected in the KeePass process.

Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment

Windows memory hacking library

Native syscall shellcode injector using HellsGate/HalosGate/TartarusGate for undetectable execution, with external shellcode loading and EDR evasion…

Suite for reverse shell handling geared toward working within the native shell