
RunPE
C# Reflective loader for unmanaged binaries.

C# Reflective loader for unmanaged binaries.

Clusters and elements to attach to MISP events or attributes (like threat actors)

Open-source framework for red-teaming generative AI systems: automate attack prompts, score model responses, and audit behavior to identify security…

A font-based deception tool for red teaming, security research, and whatever else.

Tools and PoCs for Windows syscall investigation.

Stop Windows Defender programmatically

A windows token impersonation tool

A tool to find folders excluded from AV real-time scanning using a time oracle

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

A payload delivery system which embeds payloads in an executable's icon file!

C# obfuscator that bypass windows defender

Detect EDR's exceptions by inspecting processes' loaded modules

Detection rule validation

Signtool for expired certificates

Abuses Windows Filtering Platform to launch a console as NT AUTHORITY\SYSTEM or impersonate another logged-on user for privilege escalation during…

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry