
CVE-2021-40444
Malicious DOCX generator exploiting CVE-2021-40444 (Microsoft Office Word RCE) with CAB-based DLL side-loading and CAB-less RAR/WSF attack chains for…

Malicious DOCX generator exploiting CVE-2021-40444 (Microsoft Office Word RCE) with CAB-based DLL side-loading and CAB-less RAR/WSF attack chains for…

Adversary Emulation Framework

Threadless Process Injection using remote function hooking.

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

Shellcode injection technique. Given as C++ header, standalone Rust program or library.

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

OWASP Mth3l3m3nt Framework is a penetration testing aiding tool and exploitation framework. It fosters a principle of attack the web using the web as…

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

PoCs and tools for investigation of Windows process execution techniques

MD5-Monomorphic Shellcode Packer - all payloads have the same MD5 hash

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

C# Reflective loader for unmanaged binaries.

Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.