
xspawn
Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

Evasion kit for Cobalt Strike

Performing Indirect Clean Syscalls

NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)

AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64


Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.

Crystal Palace library for proxying Nt API calls via the Threadpool

Obex – Blocking unwanted DLLs in user mode

A Poc on blocking Procmon from monitoring network events

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

Call stack spoofing for Rust

HookChain: A new perspective for Bypassing EDR Solutions

Tools that trigger False Positive AV alerts

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry