Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".
Materials for the workshop "Red Team Ops: Havoc 101"
Abusing Windows fork API and OneDrive.exe process to inject the malicious shellcode without allocating new RWX memory region.
Small PoC of using a Microsoft signed executable as a lolbin.