
EtwSessionHijacking
A Poc on blocking Procmon from monitoring network events

A Poc on blocking Procmon from monitoring network events

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Evasion kit for Cobalt Strike

Performing Indirect Clean Syscalls

AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)

kill anti-malware protected processes ( BYOVD )

HookChain: A new perspective for Bypassing EDR Solutions

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

C++ self-Injecting dropper based on various EDR evasion techniques.

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Amsi Bypass payload that works on Windwos 11

Call stack spoofing for Rust

Remove API hooks from a Beacon process.

Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime