
NimBlackout
Kill AV/EDR leveraging BYOVD attack

Kill AV/EDR leveraging BYOVD attack

Terminate AV/EDR leveraging BYOVD attack

Playing around with Stratus Red Team (Cloud Attack simulation tool) and SumoLogic

A novel adversarial attack on LLM based on the Exponentiated Gradient Descent technique.

This is the tool to dump the LSASS process on modern Windows 11

Inject DLLs into the explorer process using icons

Remove API hooks from a Beacon process.

Port of Cobalt Strike's Process Inject Kit

A new simple and powerfull packer for malware

Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.

RedCloudOS is a Cloud Adversary Simulation Operating System for Red Teams to assess the Cloud Security of Leading Cloud Service Providers (CSPs)

Replaces Cobalt Strike's Sleepmask/BeaconGate with Crystal Palace PICO primitives to evade EDR and enhance post-exploitation evasion for red-team…

Lifetime AMSI bypass

Tools and PoCs for Windows syscall investigation.

A tool to find folders excluded from AV real-time scanning using a time oracle

StealthRL: RL framework for adversarially paraphrasing AI text to stress-test detector robustness.


PoCs and tools for investigation of Windows process execution techniques