
trustmebro
Bypass llm guardrails by confusing it with fabricated tool output.

Bypass llm guardrails by confusing it with fabricated tool output.

C2 profile for Mythic tunneling encrypted peer-to-peer agent traffic through IEEE 802.1AB LLDP Organizationally Specific TLVs for covert Layer 2…

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

Windows Defender patch bypass PoC for CVE-2026-50656 (RoguePlanet), demonstrating exploitability on Windows 11 25H2 and Server 2025 despite…

Python PoC for CVE-2026-21010 that replays captured SIP digest Authorization headers to bypass nonce uniqueness/expiration and make unauthorized VoIP…

Proof-of-concept exploit for CVE-2026-21003 demonstrating JWT authentication bypass by omitting the kid header and using the 'none' algorithm to…

Educational Python PoC for a QUIC address-validation bypass that triggers handshake amplification, including vulnerable server simulation and attack…

Exploit PoC and vulnerable admission webhook for CVE-2026-5556, demonstrating Kubernetes admission controller bypass via case-sensitive pod name…

CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.

reverse engineering Gemini's SynthID detection

Evasion kit for Cobalt Strike

Performing Indirect Clean Syscalls

NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)

AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64

Multi-stage prompt injection technique that bypasses LLM safety alignment via identity reassignment, refusal suppression, and output coercion,…


Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.