
memdumper
Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

CVE-2025-61155 — arbitrary process termination in GameDriverX64.sys (Tower of Fantasy anti-cheat). Original IDA Pro teardown, PoC, YARA, IOCs,…

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

PoCs and tools for investigation of Windows process execution techniques

Burp Plugin to Bypass WAFs through the insertion of Junk Data

👁🗨 This script will simulate fake processes of analysis sandbox/VM software that some malware will try to avoid.

Stealth Windows process enumeration PoC that lists PIDs using NTFS via NtQueryInformationFile, bypassing standard monitoring APIs and enabling EDR…

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Venom is a library that meant to perform evasive communication using stolen browser socket

Windows x64 kernel mode rootkit process hollowing POC.

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

Red-team EDR evasion utility that terminates security services by abusing Process Explorer driver functionality to bypass PPL and ObRegisterCallbacks.

Test cases for broken MIME and tools to generate and process these

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions