
Unwinder
Call stack spoofing for Rust

Call stack spoofing for Rust

Signtool for expired certificates

Abuses Windows Filtering Platform to launch a console as NT AUTHORITY\SYSTEM or impersonate another logged-on user for privilege escalation during…

Hardware breakpoint hooking engine for Windows that uses debug registers to hook functions, bypass ETW/AMSI, and evade user-land EDR monitoring.

A productionized greedy coordinate gradient (GCG) attack tool for large language models (LLMs)

A PoC implementation for dynamically masking call stacks with timers.

PowerShell proof-of-concept that bypasses Windows User Account Control (UAC) to elevate privileges, intended for authorized penetration testing and…

Public Repo for Atomic Test Harness

A simple ptrace-less shared library injector for x64 Linux

PoC for Windows privilege escalation and code injection using OfficeClickToRun RPC and undocumented shim manipulation to inject DLLs into SYSTEM…

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

Cobalt Strike BOF collection for attacking Azure AD during red team operations, covering authentication, enumeration, and post-exploitation vectors.

reverse engineering SynthID for text

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

See adversary, do adversary: Simple execution of commands for defensive tuning/research (now with more ELF on the shelf)

Crystal Palace library for proxying Nt API calls via the Threadpool