
APTSimulator
A toolset to make a system look as if it was the victim of an APT attack

A toolset to make a system look as if it was the victim of an APT attack

During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system…

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

RedCloudOS is a Cloud Adversary Simulation Operating System for Red Teams to assess the Cloud Security of Leading Cloud Service Providers (CSPs)

Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting

Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

Apply a divide and conquer approach to bypass EDRs

Patch AMSI and ETW

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

Bypass the Event Trace Windows(ETW) and unhook ntdll.

A payload delivery system which embeds payloads in an executable's icon file!

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

Proof-of-concept exploit for CVE-2026-22003 demonstrating Redis Lua sandbox escape via debug.sethook to execute arbitrary system commands.

Kernel-mode hook that intercepts, decrypts, and nullifies BEDaisy-to-service report traffic to suppress anti-cheat detection on UEFI and non-UEFI…

Performing Indirect Clean Syscalls