
HintInject
A PoC project for embedding shellcode to Hint/Name Table

A PoC project for embedding shellcode to Hint/Name Table

REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in…

WPTaskScheduler RPC Persistence & CVE-2024-49039 via Task Scheduler

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

DLL sideloading/proxying with Nim!

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

HTTP Server serving obfuscated Powershell Scripts/Payloads

Local privilege escalation exploit for CVE-2020-1066 targeting Windows 7 and Server 2008 R2. Leverages arbitrary file replacement via Windows…

A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…


A rust library that allows you to host the CLR and execute dotnet binaries.

Hijacks code execution via overwriting Control Flow Guard pointers in combase.dll

Windows local privilege escalation exploit abusing SeManageVolumePrivilege to grant full C:\ drive access and gain a SYSTEM shell via PrintConfig.dll…

Local PE injection technique using hardware breakpoints and vectored exception handling to manipulate DLL loading and execute arbitrary payloads, as…

Some Rust program I wrote while learning Malware Development

Reverse NTP remote access trojan in python, for penetration testers