
RemoteMonologue
Weaponizing DCOM for NTLM Authentication Coercions

Weaponizing DCOM for NTLM Authentication Coercions

AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64

I Know Where Your Page Lives: Derandomizing the latest Windows 10 Kernel - ZeroNights 2016

Detect EDR's exceptions by inspecting processes' loaded modules

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

A comprehensive set of fairness metrics for datasets and machine learning models, explanations for these metrics, and algorithms to mitigate bias in…

A tool to find folders excluded from AV real-time scanning using a time oracle

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.

A toolset to make a system look as if it was the victim of an APT attack

An information security preparedness tool to do adversarial simulation.

Purple-team telemetry & simulation toolkit.

Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).