
meterssh
MeterSSH is a way to take shellcode, inject it into memory then tunnel whatever port you want to over SSH to mask any type of communications as a…

MeterSSH is a way to take shellcode, inject it into memory then tunnel whatever port you want to over SSH to mask any type of communications as a…

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

Proof-of-concept obfuscation toolkit for C# post-exploitation tools

Threadless Process Injection using remote function hooking.

Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin…

A Bind Shell Using the Fax Service and a DLL Hijack

A tool to transform Chromium browsers into a C2 Implant

PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

Meterpreter Paranoid Mode - SSL/TLS connections

Local privilege escalation exploit for CVE-2023-21768 targeting Windows AFD driver. Elevates arbitrary process to SYSTEM using I/O Ring read/write…


A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

some gadgets about windows process and ready to use :)

Kernel exploit for Xbox SystemOS using CVE-2024-30088

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

From XSS to RCE 2.75 - Black Hat Europe Arsenal 2017 + Extras

Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.