
Dumpy
Reuse open handles to dynamically dump LSASS.

Reuse open handles to dynamically dump LSASS.

Red team tool for EDR evasion: dynamically resolves syscall IDs, patches ntdll stubs, unhooks IAT hooks, and lists hooked APIs from major EDR vendors.

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles

Load your driver like win32k.sys

PowerSploit - A PowerShell Post-Exploitation Framework

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

Tools and PoCs for Windows syscall investigation.

A prototype malware C2 channel using x509 certificates over mTLS

Shellcode Loader with Indirect Dynamic syscall Implementation , shellcode in MAC format, API resolving from PEB, Syscall calll and syscall…

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

different ntdll unhooking techniques : unhooking ntdll from disk, from KnownDlls, from suspended process, from remote server (fileless)

Educational deep dive into macOS app bundles, plist files, and launchd process behavior, with offensive security notes on packaging payloads as .app…

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

Obex – Blocking unwanted DLLs in user mode

Remove API hooks from a Beacon process.

Remove API hooks from a Beacon process.