
watermarks-remover
Strip multi-vendor AI provenance marks: Unicode text hygiene, statistical rewrite hooks, and C2PA/metadata from PNG/JPEG/SVG/PDF/DOCX/HTML/MD

Strip multi-vendor AI provenance marks: Unicode text hygiene, statistical rewrite hooks, and C2PA/metadata from PNG/JPEG/SVG/PDF/DOCX/HTML/MD

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes

Red Team K8S Adversary Emulation Based on kubectl

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

Tools and PoCs for Windows syscall investigation.

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

Remove API hooks from a Beacon process.

Obex – Blocking unwanted DLLs in user mode

Python3 utility for creating zip files that smuggle additional data for later extraction

Load your driver like win32k.sys

PoC code from DEF CON 25 presentation

A tool to find folders excluded from AV real-time scanning using a time oracle