
AMSI-ETW-Patch
Patch AMSI and ETW

Patch AMSI and ETW


Venom is a library that meant to perform evasive communication using stolen browser socket

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel space

A prototype malware C2 channel using x509 certificates over mTLS

I have documented all of the AMSI patches that I learned till now

HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.

Apply a divide and conquer approach to bypass EDRs

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

Small PoC of using a Microsoft signed executable as a lolbin.

Win32 and Kernel abusing techniques for pentesters

This map lists the essential techniques to bypass anti-virus and EDR

Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

Shellcode Loader with Indirect Dynamic syscall Implementation , shellcode in MAC format, API resolving from PEB, Syscall calll and syscall…