
ThreadlessInject
Threadless Process Injection using remote function hooking.

Threadless Process Injection using remote function hooking.

Performing Indirect Clean Syscalls

This is the tool to dump the LSASS process on modern Windows 11

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

Protection against Model Serialization Attacks

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

Inject DLLs into the explorer process using icons

kill anti-malware protected processes ( BYOVD )

Stop Windows Defender programmatically

PoC code from DEF CON 25 presentation

A PoC ransomware sample to test out your ransomware response strategy.

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

Remove API hooks from a Beacon process.

C++ self-Injecting dropper based on various EDR evasion techniques.

Project Mantis: Hacking Back the AI-Hacker; Prompt Injection as a Defense Against LLM-driven Cyberattacks

Obex – Blocking unwanted DLLs in user mode

A POC to disable TamperProtection and other Defender / MDE components