
no-defender
A slightly more fun way to disable windows defender + firewall. (through the WSC api)

A slightly more fun way to disable windows defender + firewall. (through the WSC api)

Build guide for Red Teaming home lab. GOAD lab setup in Proxmox and pfSense, Operator/C2 and Redirectors.

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

Performing Indirect Clean Syscalls

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)

kill anti-malware protected processes ( BYOVD )

HookChain: A new perspective for Bypassing EDR Solutions

Evasion kit for Cobalt Strike

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

C++ self-Injecting dropper based on various EDR evasion techniques.

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Amsi Bypass payload that works on Windwos 11

Call stack spoofing for Rust

Remove API hooks from a Beacon process.

Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…