
TimeException
A tool to find folders excluded from AV real-time scanning using a time oracle

A tool to find folders excluded from AV real-time scanning using a time oracle

A productionized greedy coordinate gradient (GCG) attack tool for large language models (LLMs)

Security benchmark for evaluating OpenClaw agents against adversarial execution contexts including poisoned files, injected skills, misleading tool…

A DNS spoofer tool written in Python3.

Evaluation framework that tests whether large language models follow invisible Unicode-encoded instructions embedded in normal-looking text, with…

A diagnostic framework for measuring LLM vulnerability to Affective Contextual Erosion (ACE) and related liminal attack vectors. **Delirium** is not…

CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.

Clusters and elements to attach to MISP events or attributes (like threat actors)

C# obfuscator that bypass windows defender

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Generate Linux executables that simulate adversary behaviors and techniques for testing detection and response coverage. Consumes JSON for easy…

Tools and PoCs for Windows syscall investigation.

Abuses Windows Filtering Platform to launch a console as NT AUTHORITY\SYSTEM or impersonate another logged-on user for privilege escalation during…

Detect EDR's exceptions by inspecting processes' loaded modules

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

A payload delivery system which embeds payloads in an executable's icon file!

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Detection rule validation