
EDRSilencer
A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

A Poc on blocking Procmon from monitoring network events

Kernel-mode hook that intercepts, decrypts, and nullifies BEDaisy-to-service report traffic to suppress anti-cheat detection on UEFI and non-UEFI…

HookChain: A new perspective for Bypassing EDR Solutions

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

Performing Indirect Clean Syscalls

AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)

kill anti-malware protected processes ( BYOVD )

Evasion kit for Cobalt Strike

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

C++ self-Injecting dropper based on various EDR evasion techniques.

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Amsi Bypass payload that works on Windwos 11

Call stack spoofing for Rust

Remove API hooks from a Beacon process.

Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime