Skip to content
Change the repository type filter

All

    Repositories list

    • 3LayersPersistence

      Public
      Demonstrating 3 persistence layers from a single EXE, that converts itself into proxy DLLs at runtime
      C
      MIT License
      128400Updated Mar 29, 2026Mar 29, 2026
    • QRSteganography

      Public
      Encodes arbitrary data into one or more QR code PNGs and decodes them back as a form of steganography for data obfuscation.
      C
      MIT License
      64600Updated Mar 10, 2026Mar 10, 2026
    • DumpBrowserSecrets

      Public
      Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from modern Chr…
      C
      MIT License
      10169100Updated Feb 14, 2026Feb 14, 2026
    • GitLabDeviceCodePhishing

      Public
      A tool to easily perform GitLab Device Code Phishing on red team engagements
      Python
      MIT License
      35000Updated Feb 9, 2026Feb 9, 2026
    • GitHubDeviceCodePhishing

      Public
      A tool to easily perform GitHub Device Code Phishing on red team engagements
      Python
      MIT License
      119200Updated Feb 9, 2026Feb 9, 2026
    • PrefetchFileParser

      Public
      A lightweight Windows Prefetch file parser to extract programs' execution history
      C
      MIT License
      86800Updated Jan 12, 2026Jan 12, 2026
    • DumpChromeSecrets

      Public archive
      Extract data from modern Chrome versions, including refresh tokens, cookies, saved credentials, autofill data, browsing history, and bookmarks
      C
      MIT License
      7755600Updated Jan 8, 2026Jan 8, 2026
    • GhostlyHollowingViaTamperedSyscalls2

      Public
      Implementing Ghostly-Hollowing using tampered syscalls for remote PE injection
      C
      MIT License
      157400Updated Dec 26, 2025Dec 26, 2025
    • ElectronVulnScanner

      Public
      Automatically scan the file system to identify Electron applications vulnerable to ASAR tampering.
      C
      MIT License
      1115900Updated Nov 28, 2025Nov 28, 2025
    • MaldevAcademyLdr.2

      Public
      RunPE implementation with multiple evasive techniques (2)
      C
      MIT License
      3728000Updated Sep 25, 2025Sep 25, 2025
    • Bypass user-land hooks by syscall tampering via the Trap Flag
      C
      MIT License
      2113900Updated Aug 25, 2025Aug 25, 2025
    • Generate an Alphabetical Polymorphic Shellcode
      C
      MIT License
      2413900Updated Aug 19, 2025Aug 19, 2025
    • Convert your shellcode into an ASCII string
      C
      MIT License
      2912800Updated Jun 27, 2025Jun 27, 2025
    • Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials
      C
      MIT License
      195400Updated May 12, 2025May 12, 2025
    • Injecting DLL into LSASS at boot
      C
      GNU General Public License v3.0
      3715600Updated Apr 29, 2025Apr 29, 2025
    • Extract and execute a PE embedded within a PNG file using an LNK file.
      Python
      MIT License
      7546512Updated Nov 2, 2024Nov 2, 2024
    • Embed a payload inside a PNG file
      C
      MIT License
      5637100Updated Oct 24, 2024Oct 24, 2024
    • Create Anti-Copy DRM Malware
      C
      MIT License
      147300Updated Aug 19, 2024Aug 19, 2024
    • Demo showcasing Maldev Academy’s code search database
      C
      MIT License
      54200Updated Feb 20, 2024Feb 20, 2024
    • Utilizing TLS callbacks to execute a payload without spawning any threads in a remote process
      C
      MIT License
      5028810Updated Jan 21, 2024Jan 21, 2024
    • Christmas

      Public
      PoC demonstrating a multi process injection chain aimed at remotely executing shellcode
      C
      MIT License
      3525910Updated Jan 21, 2024Jan 21, 2024
    • RunPE implementation with multiple evasive techniques (1)
      C
      MIT License
      5138400Updated Sep 22, 2023Sep 22, 2023
    • HellHall

      Public
      Performing Indirect Clean Syscalls
      C
      8060611Updated Apr 19, 2023Apr 19, 2023
    ProTip! When viewing an organization's repositories, you can use the props. filter to filter by custom property.