
xspawn
Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

A slightly more fun way to disable windows defender + firewall. (through the WSC api)

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

kill anti-malware protected processes ( BYOVD )

Performing Indirect Clean Syscalls

HookChain: A new perspective for Bypassing EDR Solutions

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)

Evasion kit for Cobalt Strike

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

C++ self-Injecting dropper based on various EDR evasion techniques.

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Call stack spoofing for Rust

Amsi Bypass payload that works on Windwos 11