
AtomicSyscall
Tools and PoCs for Windows syscall investigation.

Tools and PoCs for Windows syscall investigation.

A windows token impersonation tool

A tool to find folders excluded from AV real-time scanning using a time oracle

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

Detect EDR's exceptions by inspecting processes' loaded modules

Detection rule validation

Abuses Windows Filtering Platform to launch a console as NT AUTHORITY\SYSTEM or impersonate another logged-on user for privilege escalation during…

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

Python PoC for CVE-2026-21010 that replays captured SIP digest Authorization headers to bypass nonce uniqueness/expiration and make unauthorized VoIP…

A DNS spoofer tool written in Python3.

CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.


An information security preparedness tool to do adversarial simulation.

PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows…

Malware Mutation Using Reinforcement Learning and Generative Adversarial Networks