
EfiGuard
Disable PatchGuard and Driver Signature Enforcement at boot time

Disable PatchGuard and Driver Signature Enforcement at boot time

Enumerate and disable common sources of telemetry used by AV/EDR.

C# Azure Function with an HTTP trigger that generates obfuscated PowerShell snippets that break or disable AMSI for the current process.

Kernel-level tool to disable Sysmon and Windows Event Logging via driver-based hook injection, enabling stealthy post-exploitation operations on…

Generate an obfuscated DLL that will disable AMSI & ETW

Instantly disable Touch ID and lock your Mac with one click or keyboard shortcut.

Permanently disable EDRs as local admin

Proof-of-concept demonstrating methods to disable or bypass Windows Defender by hiding, locking, or protecting its folders, enabling persistence…

Paranoid disable whole AF_ALG + algif_* modules - Copy Fail (CVE-2026-31431)

Paranoid disable Linux IPsec ESP support (esp4/esp6) and RxRPC support.

Intune Proactive Remediation scripts to enforce patched Adobe Acrobat/Reader versions and disable JavaScript to mitigate CVE-2026-34621 exploitation.

A small powershell script to disable print spooler service using desired state configuration

Exploit script for CVE-2017-0290 targeting Windows Defender on Windows 8.1/10, designed to disable or bypass the built-in antivirus protection.

This simple PowerShell script is in response to the "PrintNightmare" vulnerability. This was designed to give a end user the ability to stop and…

Simple batch script to disable the Microsoft Print Spooler service from system

Hardentools simply reduces the attack surface on Microsoft Windows computers by disabling low-hanging fruit risky features.

AppLocker-Based EDR Neutralization