
process-inject-kit
Port of Cobalt Strike's Process Inject Kit

Port of Cobalt Strike's Process Inject Kit

Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC

Anti-LLM obfuscation via finger counting

A tool to find folders excluded from AV real-time scanning using a time oracle

A productionized greedy coordinate gradient (GCG) attack tool for large language models (LLMs)

A Poc on blocking Procmon from monitoring network events

Collection of VBA macro published in our twitter / blog

See adversary, do adversary: Simple execution of commands for defensive tuning/research (now with more ELF on the shelf)

Purpleteam scripts simulation & Detection - trigger events for SOC detections

Windows 7 UAC Bypass Vulnerability in the Windows Script Host

Improved version of EKKO by @5pider that Encrypts only Image Sections

C2 redirector base on caddy

Detect EDR's exceptions by inspecting processes' loaded modules

Terminate AV/EDR leveraging BYOVD attack

Kali365 - EvilTokens Replica

A technique to coerce a Windows SQL Server to authenticate on an arbitrary machine.

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post