
EtwSessionHijacking
A Poc on blocking Procmon from monitoring network events

A Poc on blocking Procmon from monitoring network events

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

Performing Indirect Clean Syscalls

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)

kill anti-malware protected processes ( BYOVD )

Evasion kit for Cobalt Strike

HookChain: A new perspective for Bypassing EDR Solutions

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

C++ self-Injecting dropper based on various EDR evasion techniques.

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Amsi Bypass payload that works on Windwos 11

Remove API hooks from a Beacon process.

Call stack spoofing for Rust

Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

Load your driver like win32k.sys