
pocKeycloakCVE-2023-0264
authenticationdefensive-toolsexploitation+7

A proof of concept for abusing exception handlers to hook and bypass user mode EDR hooks.

An ssh honeypot with the XZ backdoor. CVE-2024-3094

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…


Kernel-level tool to disable Sysmon and Windows Event Logging via driver-based hook injection, enabling stealthy post-exploitation operations on…