Stars
Custom Adaptix-compatible C2 agent - PIC beacon + Stardust UDRL + Go extender plugins
The first comprehensive book dedicated to modern UEFI bootkit and kernel-mode rootkit development.
GPT Disk Image Creator for UEFI Development, with EFI System Partition and FAT32 Filesystem
DSCourier is a proof-of-concept that uses the WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries.
A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.
Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by BeichenDream.
Defender Signature Update Race Condition LPE
Automatically discover relationships between UEFI Settings and NVRAM variables
LeechCore - Physical Memory Acquisition Library & The LeechAgent Remote Memory Acquisition Agent
iOS <=26.0.1 DarkSword Kernel Exploit reimplemented in Objective-C
Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.
Small set of drivers to retrieve SMM related information
Starter pack for learning how to develop UEFI bootkits: basic proof-of-concepts, development environment configuration, and step-by-step resources to begin coding low-level bootkit components from …
A curated compilation of extensive resources dedicated to bootkit and rootkit development.
Este es un pequeño repositorio para crear una inyeccion de DLL, es un proyecto pensado para una prueba de concepto, con motivos educativos y de aprendizaje
This is only for learn about drivers on Windows
PIC shellcode (C/C++) development toolkit designed for malware developers.
PICO-Implant is a Proof of Concept C2 implant built using Position-independent Code Objects (PICO) for modular functionality. This project demonstrates that It's possible to build a multi-stage and…
The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.