
TangledWinExec
PoCs and tools for investigation of Windows process execution techniques

PoCs and tools for investigation of Windows process execution techniques

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Burp Plugin to Bypass WAFs through the insertion of Junk Data

👁🗨 This script will simulate fake processes of analysis sandbox/VM software that some malware will try to avoid.

Red-team EDR evasion utility that terminates security services by abusing Process Explorer driver functionality to bypass PPL and ObRegisterCallbacks.

Windows x64 kernel mode rootkit process hollowing POC.

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Test cases for broken MIME and tools to generate and process these

Venom is a library that meant to perform evasive communication using stolen browser socket

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

Stealth Windows process enumeration PoC that lists PIDs using NTFS via NtQueryInformationFile, bypassing standard monitoring APIs and enabling EDR…

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

CVE-2025-61155 — arbitrary process termination in GameDriverX64.sys (Tower of Fantasy anti-cheat). Original IDA Pro teardown, PoC, YARA, IOCs,…