
EDRPrison
Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Red Team K8S Adversary Emulation Based on kubectl

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

C++ self-Injecting dropper based on various EDR evasion techniques.

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).

A guided mutation-based fuzzer for ML-based Web Application Firewalls

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

Reverse Shell Detection with Machine Learning

Practical black-box adversarial packet generation against encrypted traffic classification with minimal overhead and full packet recoverability.