
Amsi-Killer
Lifetime AMSI bypass

Lifetime AMSI bypass

reverse engineering Gemini's SynthID detection

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

Resolves Windows APIs at runtime using vectored exception handlers and hashed lookups to hide imports and slow reverse engineering of offensive…

reverse engineering SynthID for text

Bluetooth keystroke injection exploit PoCs for CVE-2023-45866, CVE-2024-21306, and CVE-2024-0230 targeting Android, Linux, macOS, and iOS via…

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Tools and PoCs for Windows syscall investigation.

Mutates signed Windows binaries to retain valid catalog signatures while changing file hashes, bypassing hash-based endpoint blocks and exposing…

Anti-LLM obfuscation via finger counting

Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC

a small wiper malware programmed in c#

Create Anti-Copy DRM Malware

PoC MSI payload based on ASEC/AhnLab's blog post

Curated reading list and taxonomy of attack and defense research for mobile on-device AI systems, covering adversarial, backdoor, model stealing, and…