
SkeletonKey
CVE-2026-6765 · Test only FormAutofill handlers exposed in Firefox

CVE-2026-6765 · Test only FormAutofill handlers exposed in Firefox
Strip multi-vendor AI provenance marks: Unicode text hygiene, statistical rewrite hooks, and C2PA/metadata from PNG/JPEG/SVG/PDF/DOCX/HTML/MD

Ghostsplice repository: PoC for Cross-Channel Trust Fragmentation Attack

Load your driver like win32k.sys


Tools and PoCs for Windows syscall investigation.

ShellcodeFluctuation PoC ported to Nim

A tool to find folders excluded from AV real-time scanning using a time oracle

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Port of Cobalt Strike's Process Inject Kit

Python3 utility for creating zip files that smuggle additional data for later extraction

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.