-
BYOVD Public
BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501).
-
AxHunter Public
PoCs for Wellbia XIGNCODE3 anti-cheat xhunter driver family - xhunter1.sys v2023.12.7.78 and xhunter2.sys v2026.6.1.192 (CVE-2026-15430, CVE-2026-3609).
-
BlackSnufkin.github.io Public
Blog and stuff https://blacksnufkin.github.io
-
Maverick Public
Adaptix C2 agent using Crystal Palace PIC linker and PICO module system
-
-
CredsHunter Public
PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping
-
LitterBox Public
A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end to end.
-
Cheshire Public
Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.
-
GeckoDroid Public
Android Client for AdaptixC2
-
DeadManSwitch Public
DeadManSwitch in rust with several triggers (remote local and network)
-
HolyGrail Public
BYOVD hunter to help prioritize windows drivers worth manual analysis
-
PoC-in-GitHub Public
Forked from nomi-sec/PoC-in-GitHub📡 PoC auto collect from GitHub.
⚠️ Be careful Malware.6 UpdatedAug 10, 2025 -
NyxInvoke Public
NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support
-
Rusty-Playground Public
Some Rust program I wrote while learning Malware Development
-
CheckPlz Public
Scan files for potential threats while leveraging AMSI (Antimalware Scan Interface) and Windows Defender. By isolating malicious content.
-
-
NovaLdr Public
Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)
-
Invoke-DumpMDEConfig Public
PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )
-
GhostDriver Public
yet another AV killer tool using BYOVD
-
0day Public
Forked from helloexp/0day各种CMS、各种平台、各种系统、各种软件漏洞的EXP、POC ,该项目将持续更新
-
LSTAR-EN Public
Forked from moscowchill/LSTAR-ENLSTAR - CobaltStrike Translated to EN
-
OdinEye Public
Create a private Discord CTI "Dashboard" using various Discord bots It,'s a simple and effective way to stay informed and up-to-date on the latest developments and news in Offensive Security World
-
PwnBox-Kali Public
Bash Script to automate the process of setting up a new Kali Linux virtual machine to look a like HTB PwnBox
-
PT-ToolKit Public
Exploits Scripts and other tools that are useful during Penetration-Testing or Red Team engagement


