
NTDLLReflection
Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

Load your driver like win32k.sys

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

Obex – Blocking unwanted DLLs in user mode

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Apply a divide and conquer approach to bypass EDRs

Patch AMSI and ETW

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…


Improved version of EKKO by @5pider that Encrypts only Image Sections

Bypass the Event Trace Windows(ETW) and unhook ntdll.

Crystal Palace library for proxying Nt API calls via the Threadpool

NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs


Tools that trigger False Positive AV alerts

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.