
Terminator_Killer
Kernel-mode process killer exploiting CVE-2026-0828 (BYOVD) to terminate protected processes via a vulnerable signed driver, bypassing PPL and…

Kernel-mode process killer exploiting CVE-2026-0828 (BYOVD) to terminate protected processes via a vulnerable signed driver, bypassing PPL and…

Reuse open handles to dynamically dump LSASS.

Red team tool for EDR evasion: dynamically resolves syscall IDs, patches ntdll stubs, unhooks IAT hooks, and lists hooked APIs from major EDR vendors.

Tools and PoCs for Windows syscall investigation.

This repo contains : simple shellcode Loader , Encoders (base64 - custom - UUID - IPv4 - MAC), Encryptors (AES), Fileless Loader (Winhttp, socket)

yet another sleep encryption thing. also used the default github repo name for this one.

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Offensive Windows BYOVD tool exploiting ECHOAC anti-cheat driver for kernel read/write, removing EDR callbacks/ETW providers, and escalating…

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

Suspend EDR and antimalware processes on Windows by exploiting WerFaultSecure, enabling temporary defense evasion in user mode without requiring…

Red teaming tool to dump LSASS memory, bypassing basic countermeasures.

A high-performance port spoofing tool built in Rust. Confuse port scanners with dynamic service emulation across all ports. Features customizable…

Tunnels IP traffic over ICMP echo packets to bypass firewalls and NAT, enabling covert data exfiltration and network pivoting during penetration…

Cross-platform Node.js CLI using Frida to forcibly inject JVM agents into Java processes, bypassing the disabled attach API for red team operations.

Socks5/4/4a Proxy support for Remote Desktop Protocol / Terminal Services / Citrix / XenApp / XenDesktop

Framework for transporting and loading encrypted Linux kernel modules, enabling stealthy implant delivery with built-in EDR and forensics evasion.

Proof-of-concept and mass scanning toolkit for CVE-2025-29927, a Next.js middleware authorization bypass via forged x-middleware-subrequest header.…