
AtomicSyscall
Tools and PoCs for Windows syscall investigation.

Tools and PoCs for Windows syscall investigation.

PoCs and tools for investigation of Windows process execution techniques

Bluetooth keystroke injection exploit PoCs for CVE-2023-45866, CVE-2024-21306, and CVE-2024-0230 targeting Android, Linux, macOS, and iOS via…

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

Mutates signed Windows binaries to retain valid catalog signatures while changing file hashes, bypassing hash-based endpoint blocks and exposing…

Curated reading list and taxonomy of attack and defense research for mobile on-device AI systems, covering adversarial, backdoor, model stealing, and…

reverse engineering Gemini's SynthID detection

Performing Indirect Clean Syscalls

reverse engineering SynthID for text

A security scanner for your LLM agentic workflows

Lifetime AMSI bypass

Signtool for expired certificates

Windows 11 24H2-25H2 Runtime PatchGuard Bypass

Anti-LLM obfuscation via finger counting

Create Anti-Copy DRM Malware

Different methods to detect a virtualized environment or potential debugging