
SharpBlackout
Terminate AV/EDR leveraging BYOVD attack

Terminate AV/EDR leveraging BYOVD attack

RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging

PoC for Windows privilege escalation and code injection using OfficeClickToRun RPC and undocumented shim manipulation to inject DLLs into SYSTEM…

A POC to disable TamperProtection and other Defender / MDE components

Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.

Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap

Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes

Command-line utility for Windows that enables SeTakeOwnershipPrivilege and modifies file ownership to the current user, granting access to otherwise…

A PoC implementation for dynamically masking call stacks with timers.


Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

ShellcodeFluctuation PoC ported to Nim

Hides reflective payloads in GPU memory via CUDA APIs, wiping host memory during sleep and using a VEH handler to restore executable memory, evading…

D/Invoke implementation in Nim