
evillimiter
Tool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access

Tool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access

Using TCP Fast Open to bypass syscall-based networking rules (CVE-2026-63828/CVE-2026-72243 PoC)

A Proof-of-Concept demonstrating the application of 3D Navier-Stokes CTT formulations to packet flow optimization and defensive bypass.

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Windows Defender 0day proof-of-concept demonstrating a patch bypass for CVE-2026-69414, targeting Windows 11 25H2 and Server 2025 to evade endpoint…

ThrottleStop.sys Arbitrary Physical Memory R/W

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

C++ library that retrieves and spoofs Windows syscall arguments using hardware breakpoints and exception handlers to subvert EDR telemetry.

Red-team EDR evasion utility that terminates security services by abusing Process Explorer driver functionality to bypass PPL and ObRegisterCallbacks.

Hands-on red-team obfuscation workshop teaching AMSI bypass, ETW evasion, and payload obfuscation with PowerShell, Visual Basic, and C# to evade…

NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

List of Awesome CobaltStrike Resources

Tools and PoCs for Windows syscall investigation.