
FalsePositives
Tools that trigger False Positive AV alerts

Tools that trigger False Positive AV alerts

Kernel-mode hook that intercepts, decrypts, and nullifies BEDaisy-to-service report traffic to suppress anti-cheat detection on UEFI and non-UEFI…

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

Build guide for Red Teaming home lab. GOAD lab setup in Proxmox and pfSense, Operator/C2 and Redirectors.

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

C2 profile for Mythic tunneling encrypted peer-to-peer agent traffic through IEEE 802.1AB LLDP Organizationally Specific TLVs for covert Layer 2…

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

Load your driver like win32k.sys

A slightly more fun way to disable windows defender + firewall. (through the WSC api)

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

A guided mutation-based fuzzer for ML-based Web Application Firewalls

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Apply a divide and conquer approach to bypass EDRs

HookChain: A new perspective for Bypassing EDR Solutions

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)