
Ghost-In-The-Logs
Kernel-level tool to disable Sysmon and Windows Event Logging via driver-based hook injection, enabling stealthy post-exploitation operations on…
defensive-toolsids-ips-evasionprivilege-escalation
626

Kernel-level tool to disable Sysmon and Windows Event Logging via driver-based hook injection, enabling stealthy post-exploitation operations on…


A proof of concept for abusing exception handlers to hook and bypass user mode EDR hooks.

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

An ssh honeypot with the XZ backdoor. CVE-2024-3094
