
RunPE
C# Reflective loader for unmanaged binaries.

C# Reflective loader for unmanaged binaries.

Clusters and elements to attach to MISP events or attributes (like threat actors)

Open-source framework for red-teaming generative AI systems: automate attack prompts, score model responses, and audit behavior to identify security…

Tools and PoCs for Windows syscall investigation.

A windows token impersonation tool

A tool to find folders excluded from AV real-time scanning using a time oracle

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

A payload delivery system which embeds payloads in an executable's icon file!

Detection rule validation

Abuses Windows Filtering Platform to launch a console as NT AUTHORITY\SYSTEM or impersonate another logged-on user for privilege escalation during…

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

This is the tool to dump the LSASS process on modern Windows 11

Proof-of-concept exploit for CVE-2026-21003 demonstrating JWT authentication bypass by omitting the kid header and using the 'none' algorithm to…

Python PoC for CVE-2026-21010 that replays captured SIP digest Authorization headers to bypass nonce uniqueness/expiration and make unauthorized VoIP…

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.