
RunAs-Stealer
RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging

RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging

Amsi Bypass payload that works on Windwos 11

macOS Initial Access Payload Generator

Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime

Load your driver like win32k.sys

Mutates signed Windows binaries to retain valid catalog signatures while changing file hashes, bypassing hash-based endpoint blocks and exposing…

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

A delicious, but malicious SSL-VPN server 🌮

Hides reflective payloads in GPU memory via CUDA APIs, wiping host memory during sleep and using a VEH handler to restore executable memory, evading…

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Apply a divide and conquer approach to bypass EDRs

Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.

PE obfuscator with Evasion in mind

I Know Where Your Page Lives: Derandomizing the latest Windows 10 Kernel - ZeroNights 2016

Port of Cobalt Strike's Process Inject Kit

Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC

A Poc on blocking Procmon from monitoring network events