
lldp
C2 profile for Mythic tunneling encrypted peer-to-peer agent traffic through IEEE 802.1AB LLDP Organizationally Specific TLVs for covert Layer 2…

C2 profile for Mythic tunneling encrypted peer-to-peer agent traffic through IEEE 802.1AB LLDP Organizationally Specific TLVs for covert Layer 2…

Kernel-mode hook that intercepts, decrypts, and nullifies BEDaisy-to-service report traffic to suppress anti-cheat detection on UEFI and non-UEFI…

Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Tools that trigger False Positive AV alerts

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

Load your driver like win32k.sys

PoCs and tools for investigation of Windows process execution techniques

NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)


Tools and PoCs for Windows syscall investigation.

Mutates signed Windows binaries to retain valid catalog signatures while changing file hashes, bypassing hash-based endpoint blocks and exposing…

Patch AMSI and ETW

Call stack spoofing for Rust