
GhostDriver
yet another AV killer tool using BYOVD

yet another AV killer tool using BYOVD

Tools that trigger False Positive AV alerts

Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.

A unique technique to execute binaries from a password protected zip

PowerShell Remote Download Cradle Generator & Obfuscator

XLL Phishing Tradecraft

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

BYOVD proof-of-concept abusing the WHQL-signed DsArk64.sys driver for ring-0 process termination and kernel read/write via encrypted IOCTLs and…