
WSASS
This is the tool to dump the LSASS process on modern Windows 11

This is the tool to dump the LSASS process on modern Windows 11

Detection rule validation

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)

Inject DLLs into the explorer process using icons

Scripted framework for simulating over 50 MITRE ATT&CK techniques to test blue team detection capabilities. Includes Python scripts and a compiled…

PoCs and tools for investigation of Windows process execution techniques

Leak NTLM via Website tab in teams via MS Office

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

Port of Cobalt Strike's Process Inject Kit

Remove API hooks from a Beacon process.

Obex – Blocking unwanted DLLs in user mode

Threadless Process Injection using remote function hooking.

Dropping a powershell script at %HOMEPATH%\Documents\WindowsPowershell\ , that contains the implant's path , and whenever powershell process is…

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

An Open-Source Package for Textual Adversarial Attack.
