
Dumpy
Reuse open handles to dynamically dump LSASS.

Reuse open handles to dynamically dump LSASS.

Tools and PoCs for Windows syscall investigation.

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Exploitation of echo_driver.sys

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.


Red teaming tool to dump LSASS memory, bypassing basic countermeasures.

A high-performance port spoofing tool built in Rust. Confuse port scanners with dynamic service emulation across all ports. Features customizable…

Metasploit AV Evasion Tool

shouganaiyo-loader is a cross-platform Frida-based Node.js command-line tool that forces Java processes to load a Java/JVMTI agent regardless of…

Socks5/4/4a Proxy support for Remote Desktop Protocol / Terminal Services / Citrix / XenApp / XenDesktop

encrypted-linux-kernel-modules

Ability to detect suspicious activity such as (WEP/WPA/WPS) attack by sniffing the air for wireless packets.

A tool to generate Snort rules based on public IP reputation data

Sorry, this tool WAS abandoned for a while. I got stress on this thing.