
obex
Obex – Blocking unwanted DLLs in user mode

Obex – Blocking unwanted DLLs in user mode

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Python3 utility for creating zip files that smuggle additional data for later extraction

Apply a divide and conquer approach to bypass EDRs


Patch AMSI and ETW

Malware Mutation Using Reinforcement Learning and Generative Adversarial Networks

Windows 11 24H2-25H2 Runtime PatchGuard Bypass

Data from a BRAWL Automated Adversary Emulation Exercise



Execute PowerShell code at the antimalware-light protection level.


Detect EDR's exceptions by inspecting processes' loaded modules


reverse engineering SynthID for text

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.