
CallMeWin32kDriver
Load your driver like win32k.sys

Load your driver like win32k.sys

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Obex – Blocking unwanted DLLs in user mode

Apply a divide and conquer approach to bypass EDRs

Patch AMSI and ETW

A guided mutation-based fuzzer for ML-based Web Application Firewalls

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

A Poc on blocking Procmon from monitoring network events


Improved version of EKKO by @5pider that Encrypts only Image Sections

Bypass the Event Trace Windows(ETW) and unhook ntdll.

Crystal Palace library for proxying Nt API calls via the Threadpool

NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs


Tools that trigger False Positive AV alerts

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver