
Lockbit3.0-MpClient-Defender-PoC
Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC

Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC

Purpleteam scripts simulation & Detection - trigger events for SOC detections

Create Anti-Copy DRM Malware

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

Mutates signed Windows binaries to retain valid catalog signatures while changing file hashes, bypassing hash-based endpoint blocks and exposing…

A slightly more fun way to disable windows defender + firewall. (through the WSC api)

Tools and PoCs for Windows syscall investigation.

A windows token impersonation tool

Windows And Ways To Break It

A technique to coerce a Windows SQL Server to authenticate on an arbitrary machine.

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

Abuses Windows Filtering Platform to launch a console as NT AUTHORITY\SYSTEM or impersonate another logged-on user for privilege escalation during…

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting

Modern PIC implant for Windows (64 & 32 bit)

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Hardware breakpoint hooking engine for Windows that uses debug registers to hook functions, bypass ETW/AMSI, and evade user-land EDR monitoring.