
Imperva_gzip_bypass
Exploit for CVE-2021-45468, an Imperva WAF bypass.

Exploit for CVE-2021-45468, an Imperva WAF bypass.


Educational evercookie demo showing how browser storage and HTTP cache techniques can persistently re-identify a visitor.

Tunnel TCP connections through a file

AI coding agents that can't exfiltrate secrets or merge their own PRs.

Programmatically create hunting rules for deserialization exploitation with multiple keywords, gadget chains, object types, encodings, and rule types

Red team tool for EDR evasion: dynamically resolves syscall IDs, patches ntdll stubs, unhooks IAT hooks, and lists hooked APIs from major EDR vendors.

This map lists the essential techniques to bypass anti-virus and EDR

This repo covers some code execution and AV Evasion methods for Macros in Office documents

A collection of techniques, examples and a little bit of theory for manually obfuscating PowerShell scripts to achieve AV evasion, compiled for…

Win32 and Kernel abusing techniques for pentesters

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs


AV/EDR Lab environment setup references to help in Malware development

This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context…

Invoke-ArgFuscator is an open-source, cross-platform PowerShell module that helps generate obfuscated command-lines for common system-native…