


Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

Extracting Clear Text Passwords from mstsc.exe using API Hooking.

Code Execution & Persistence in NETWORK SERVICE FAX Service

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file (DLL Hijacking)

CVE-2023-6401 is a DLL hijacking vulnerability that allows attackers to execute arbitrary code by placing a malicious `dbghelp.dll` file in the…

Windows implant that steals RDP credentials via API hooking (Detours) and DLL injection, capturing usernames and passwords to a file for red-team…

Disassemble ANY files including .so (NDK, JNI), Windows PE(EXE, DLL, SYS, etc), linux binaries, libraries, and any other files such as pictures,…

A C2 post-exploitation framework

Automated DLL Sideloading Tool With EDR Evasion Capabilities

DLL Hijacking in Quickheal Total Security/ Internet Security/ Antivirus Pro (Installers)

DLL Planting in the Corsair iCUE v.5.3.102 CVE-2023-38822

DLL Planting in the CoD MW Warzone 2 - CVE-2023-38821

DLL Planting in the Slack 4.33.73 - CVE-2023-38820

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

C# PrintNightmare (CVE-2021-1675)

A POC of a new “threadless” process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote…

A dll hijacking vulnerability in zoom meeting < 5.1.4. CVE-2020-9767