
AtomicSyscall
Tools and PoCs for Windows syscall investigation.

Tools and PoCs for Windows syscall investigation.

A windows token impersonation tool

A tool to find folders excluded from AV real-time scanning using a time oracle

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

A payload delivery system which embeds payloads in an executable's icon file!

Detection rule validation

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry


This is the tool to dump the LSASS process on modern Windows 11

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.

A PoC ransomware sample to test out your ransomware response strategy.

A productionized greedy coordinate gradient (GCG) attack tool for large language models (LLMs)

A DNS spoofer tool written in Python3.

A diagnostic framework for measuring LLM vulnerability to Affective Contextual Erosion (ACE) and related liminal attack vectors. **Delirium** is not…