
AMSI-ETW-Patch
Patch AMSI and ETW

Patch AMSI and ETW

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

A Poc on blocking Procmon from monitoring network events

Bypass the Event Trace Windows(ETW) and unhook ntdll.

Tools that trigger False Positive AV alerts

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

Evasion kit for Cobalt Strike

Performing Indirect Clean Syscalls

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)

kill anti-malware protected processes ( BYOVD )

HookChain: A new perspective for Bypassing EDR Solutions

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Call stack spoofing for Rust

Remove API hooks from a Beacon process.


A slightly more fun way to disable windows defender + firewall. (through the WSC api)