
FalsePositives
Tools that trigger False Positive AV alerts

Tools that trigger False Positive AV alerts

Kernel-mode hook that intercepts, decrypts, and nullifies BEDaisy-to-service report traffic to suppress anti-cheat detection on UEFI and non-UEFI…

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

C2 profile for Mythic tunneling encrypted peer-to-peer agent traffic through IEEE 802.1AB LLDP Organizationally Specific TLVs for covert Layer 2…

Load your driver like win32k.sys

A slightly more fun way to disable windows defender + firewall. (through the WSC api)

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode


A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

Apply a divide and conquer approach to bypass EDRs

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

kill anti-malware protected processes ( BYOVD )


NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs