
EDRPrison
Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Application-scoped Windows network brownouts in native C and BOF form

Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged processes to…

Python PoC for CVE-2026-22007: NTP monlist amplification over IPv6, including a simulated vulnerable server and spoofed UDP reflection attack.

Sample code for DNS spoofing with ARP poisoning.

A delicious, but malicious SSL-VPN server 🌮

Project Mantis: Hacking Back the AI-Hacker; Prompt Injection as a Defense Against LLM-driven Cyberattacks

C2 redirector base on caddy

Evasion kit for Cobalt Strike

HookChain: A new perspective for Bypassing EDR Solutions

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Call stack spoofing for Rust

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

A Poc on blocking Procmon from monitoring network events

Crystal Palace library for proxying Nt API calls via the Threadpool

C2 profile for Mythic tunneling encrypted peer-to-peer agent traffic through IEEE 802.1AB LLDP Organizationally Specific TLVs for covert Layer 2…