
EtwSessionHijacking
A Poc on blocking Procmon from monitoring network events

A Poc on blocking Procmon from monitoring network events

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

Canary Hunter aims to be a quick PowerShell script to check for Common Canaries in various formats generated for free on canarytokens.org

Open-source cross-modal and multimodal prompt injection test suite. 250,000+ attack payloads across text, image, document, and audio modalities.…

See adversary, do adversary: Simple execution of commands for defensive tuning/research (now with more ELF on the shelf)

Bypass the Event Trace Windows(ETW) and unhook ntdll.

Crystal Palace library for proxying Nt API calls via the Threadpool

Modern PIC implant for Windows (64 & 32 bit)

NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs

A Bumblebee-inspired Crypter

a small wiper malware programmed in c#

ShellcodeFluctuation PoC ported to Nim


Tools that trigger False Positive AV alerts

PISmith: Reinforcement Learning-based Red Teaming for Prompt Injection Defenses

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged processes to…

Covert data exfiltration via DNS