
memdumper
Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

PoCs and tools for investigation of Windows process execution techniques

List of Awesome CobaltStrike Resources

Venom is a library that meant to perform evasive communication using stolen browser socket

I have documented all of the AMSI patches that I learned till now

A collection of techniques, examples and a little bit of theory for manually obfuscating PowerShell scripts to achieve AV evasion, compiled for…

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…

Lists of AMSI triggers (VBA, JScript / VBScript)

A complete Blue Team Cybersecurity Lab featuring pfSense, Suricata, and ELK Stack for network monitoring and threat detection.

CVE-2025-61155 — arbitrary process termination in GameDriverX64.sys (Tower of Fantasy anti-cheat). Original IDA Pro teardown, PoC, YARA, IOCs,…

Memory API proxy via signed mozglue.dll

A collection of awesome penetration testing resources, tools and other shiny things

SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated…

BYOVD: Use 360 WFP driver to block EDR/XDR network connection.