
InflativeLoading
Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.

Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.

2 ways of Password Filter DLL to record the plaintext password

DLL Password Filter Implant with Exfiltration Capabilities

A Bind Shell Using the Fax Service and a DLL Hijack

Converts a EXE into DLL

Yet another PoC for https://www.wietzebeukema.nl/blog/hijacking-dlls-in-windows

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

Cooolis-ms是一个包含了Metasploit Payload Loader、Cobalt Strike External C2 Loader、Reflective DLL injection的代码执行工具,它的定位在于能够在静态查杀上规避一些我们将要执行且含有特征的代码,帮助红队人员更方便快…

EternalBlue suite remade in C/C++ which includes: MS17-010 Exploit, EternalBlue vulnerability detector, DoublePulsar detector and DoublePulsar…

[Powershell with Embedded .NET Library] Program that prepares a .NET DLL Library to run embedded in Powershell Script

LoadLibrary for offensive operations

A C2 post-exploitation framework

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Generates malicious DOCX documents exploiting CVE-2021-40444 (Microsoft Office RCE) with a hosted server for DLL payload delivery, based on…

A tool for generating fake code signing certificates or signing real ones

C# based tool which automates the process of discovering and exploiting DLL Hijacks in target binaries. The Hijacked paths discovered can later be…

Automated DLL hijacking vulnerability discovery tool that analyzes PE binaries at load-time and runtime via API hooking, enumerating missing DLLs and…

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.