
bedaisy-bypass
Kernel-mode hook that intercepts, decrypts, and nullifies BEDaisy-to-service report traffic to suppress anti-cheat detection on UEFI and non-UEFI…

Kernel-mode hook that intercepts, decrypts, and nullifies BEDaisy-to-service report traffic to suppress anti-cheat detection on UEFI and non-UEFI…

Malware Mutation Using Reinforcement Learning and Generative Adversarial Networks

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Improved version of EKKO by @5pider that Encrypts only Image Sections

Tools that trigger False Positive AV alerts

HookChain: A new perspective for Bypassing EDR Solutions

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64

Obex – Blocking unwanted DLLs in user mode


CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

SecOpsMaesttro POC

Windows 11 24H2-25H2 Runtime PatchGuard Bypass

Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

Bypass the Event Trace Windows(ETW) and unhook ntdll.