
bedaisy-bypass
Kernel-mode hook that intercepts, decrypts, and nullifies BEDaisy-to-service report traffic to suppress anti-cheat detection on UEFI and non-UEFI…

Kernel-mode hook that intercepts, decrypts, and nullifies BEDaisy-to-service report traffic to suppress anti-cheat detection on UEFI and non-UEFI…

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

Load your driver like win32k.sys

A slightly more fun way to disable windows defender + firewall. (through the WSC api)

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.


Application-scoped Windows network brownouts in native C and BOF form

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

Apply a divide and conquer approach to bypass EDRs

NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

Patch AMSI and ETW

Improved version of EKKO by @5pider that Encrypts only Image Sections