
CallMeWin32kDriver
Load your driver like win32k.sys

Load your driver like win32k.sys

Abuses Windows Filtering Platform to launch a console as NT AUTHORITY\SYSTEM or impersonate another logged-on user for privilege escalation during…

Windows 11 24H2-25H2 Runtime PatchGuard Bypass

A delicious, but malicious SSL-VPN server 🌮

Alignment-research scaffold (autoresearch-style) for LLM guardrails: search over a single policy.md surface

A PoC implementation for dynamically masking call stacks with timers.

Obex – Blocking unwanted DLLs in user mode

A PoC ransomware sample to test out your ransomware response strategy.

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Kill AV/EDR leveraging BYOVD attack

Python3 utility for creating zip files that smuggle additional data for later extraction

A simple ptrace-less shared library injector for x64 Linux

PE obfuscator with Evasion in mind

RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging

I Know Where Your Page Lives: Derandomizing the latest Windows 10 Kernel - ZeroNights 2016

Project Mantis: Hacking Back the AI-Hacker; Prompt Injection as a Defense Against LLM-driven Cyberattacks