
CallStackSpoofer
A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

C++ self-Injecting dropper based on various EDR evasion techniques.

Amsi Bypass payload that works on Windwos 11

Load your driver like win32k.sys

Obex – Blocking unwanted DLLs in user mode

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Improved version of EKKO by @5pider that Encrypts only Image Sections

Crystal Palace library for proxying Nt API calls via the Threadpool

NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs


Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.



Tools and PoCs for Windows syscall investigation.

PoCs and tools for investigation of Windows process execution techniques



Detect EDR's exceptions by inspecting processes' loaded modules