Starred repositories
Azazel is a userland rootkit based off of the original LD_PRELOAD technique from Jynx rootkit. It is more robust and has additional features, and focuses heavily around anti-debugging and anti-dete…
Flipper Zero firmware source code
Flipper Zero Unleashed Firmware
A small utility to modify the dynamic linker and RPATH of ELF executables
JynxKit is an LD_PRELOAD userland rootkit for Linux systems with reverse connection SSL backdoor
Python script to enumerate users, groups and computers from a Windows domain through LDAP queries
Exploit for Grafana arbitrary file-read and RCE (CVE-2024-9264)
Fast passive subdomain enumeration tool.
POC for hikivison devices based on the following vulnerability https://www.exploit-db.com/exploits/44328
Universal Linux LKM rootkit, designed to work in any kernel version and both architectures (i686 and x86_64).
CVE-2024-28397: js2py sandbox escape, bypass pyimport restriction.
AV/EDR evasion via direct system calls.
Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a library from memory into a host process.
Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com
Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode
Advanced usermode anti-anti-debugger. Forked from https://bitbucket.org/NtQuery/scyllahide
JynxKit2 is an LD_PRELOAD userland rootkit based on the original JynxKit. The backdoor has been replaced with an "accept()" system hook.
gsmith257-cyber / better-sliver
Forked from BishopFox/sliverAdversary Emulation Framework
My experiments in weaponizing Nim (https://nim-lang.org/)
Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials
Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials
Injecting DLL into LSASS at boot
Pure Malware Development Resource Collections