
EDRPrison
Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

PowerShell proof-of-concept that bypasses Windows User Account Control (UAC) to elevate privileges, intended for authorized penetration testing and…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

A diagnostic framework for measuring LLM vulnerability to Affective Contextual Erosion (ACE) and related liminal attack vectors. **Delirium** is not…

Code repository for CS5446 project exploring defenses against jailbreak attacks on large-language models it includes datasets, notebooks,…

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

Automated behavioral evaluation framework for LLMs that generates diverse test scenarios to probe for sycophancy, bias, and other safety-relevant…

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)

Leak NTLM via Website tab in teams via MS Office

Benchmark harness measuring where prompt injection defenses fire in tool-using LLM agent pipelines, tracking canary tokens across exposed, persisted,…

A toolset to make a system look as if it was the victim of an APT attack

Privaxy is the next generation tracker and advertisement blocker. It blocks ads and trackers by MITMing HTTP(s) traffic. Also check out my new…

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

Bypass llm guardrails by confusing it with fabricated tool output.

Windows And Ways To Break It

A POC to disable TamperProtection and other Defender / MDE components

Apply a divide and conquer approach to bypass EDRs