
EtwSessionHijacking
A Poc on blocking Procmon from monitoring network events

A Poc on blocking Procmon from monitoring network events

Application-scoped Windows network brownouts in native C and BOF form

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

Performing Indirect Clean Syscalls

HookChain: A new perspective for Bypassing EDR Solutions

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

C++ self-Injecting dropper based on various EDR evasion techniques.

Remove API hooks from a Beacon process.

Call stack spoofing for Rust

Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime

Load your driver like win32k.sys

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Obex – Blocking unwanted DLLs in user mode

Apply a divide and conquer approach to bypass EDRs

Patch AMSI and ETW