
CallStackSpoofer
A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

This is the tool to dump the LSASS process on modern Windows 11

C++ self-Injecting dropper based on various EDR evasion techniques.

Bypassing UAC with SSPI Datagram Contexts

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

Fully automatic censorship removal for language models

Lifetime AMSI bypass

Inject DLLs into the explorer process using icons

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

Amsi Bypass payload that works on Windwos 11

PoC code from DEF CON 25 presentation

PrintNotifyPotato

macOS Initial Access Payload Generator

Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting

C# Reflective loader for unmanaged binaries.

A windows token impersonation tool

Signtool for expired certificates

Execute PowerShell code at the antimalware-light protection level.