
anamorpher
image scaling attacks for multi-modal prompt injection

image scaling attacks for multi-modal prompt injection

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Generate Linux executables that simulate adversary behaviors and techniques for testing detection and response coverage. Consumes JSON for easy…

C# obfuscator that bypass windows defender

Malware Mutation Using Reinforcement Learning and Generative Adversarial Networks

Tools and PoCs for Windows syscall investigation.

Abuses Windows Filtering Platform to launch a console as NT AUTHORITY\SYSTEM or impersonate another logged-on user for privilege escalation during…

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

Detect EDR's exceptions by inspecting processes' loaded modules

A payload delivery system which embeds payloads in an executable's icon file!

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Detection rule validation

Clusters and elements to attach to MISP events or attributes (like threat actors)

Open-source framework for red-teaming generative AI systems: automate attack prompts, score model responses, and audit behavior to identify security…

Stop Windows Defender programmatically

A PoC ransomware sample to test out your ransomware response strategy.

Signtool for expired certificates