
hookchain
HookChain: A new perspective for Bypassing EDR Solutions

HookChain: A new perspective for Bypassing EDR Solutions

AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Apply a divide and conquer approach to bypass EDRs

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver


PoCs and tools for investigation of Windows process execution techniques

Data from a BRAWL Automated Adversary Emulation Exercise

Attempt at Obfuscated version of SharpCollection

A technique to coerce a Windows SQL Server to authenticate on an arbitrary machine.

Adversary Emulation Framework

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Infection Monkey - An open-source adversary emulation platform

Red Team K8S Adversary Emulation Based on kubectl

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…