
AtomicSyscall
Tools and PoCs for Windows syscall investigation.

Tools and PoCs for Windows syscall investigation.

Security benchmark for evaluating OpenClaw agents against adversarial execution contexts including poisoned files, injected skills, misleading tool…

A diagnostic framework for measuring LLM vulnerability to Affective Contextual Erosion (ACE) and related liminal attack vectors. **Delirium** is not…

PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows…

An information security preparedness tool to do adversarial simulation.

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Bypass llm guardrails by confusing it with fabricated tool output.

This is the tool to dump the LSASS process on modern Windows 11

A windows token impersonation tool

C# Reflective loader for unmanaged binaries.

Signtool for expired certificates

A DNS spoofer tool written in Python3.

Python PoC for CVE-2026-21010 that replays captured SIP digest Authorization headers to bypass nonce uniqueness/expiration and make unauthorized VoIP…

Proof-of-concept exploit for CVE-2026-21003 demonstrating JWT authentication bypass by omitting the kid header and using the 'none' algorithm to…

Malware Mutation Using Reinforcement Learning and Generative Adversarial Networks

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…