
hookchain
HookChain: A new perspective for Bypassing EDR Solutions

HookChain: A new perspective for Bypassing EDR Solutions

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Call stack spoofing for Rust

Remove API hooks from a Beacon process.

Python PoC demonstrating CVE-2026-22020: exploitable weak seed in quantum key distribution privacy amplification, reducing final key entropy.

A slightly more fun way to disable windows defender + firewall. (through the WSC api)

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

C++ self-Injecting dropper based on various EDR evasion techniques.

Load your driver like win32k.sys

Obex – Blocking unwanted DLLs in user mode

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

A Poc on blocking Procmon from monitoring network events

Improved version of EKKO by @5pider that Encrypts only Image Sections

Crystal Palace library for proxying Nt API calls via the Threadpool

NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs

Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.


Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and…