
MaldevAcademyLdr.2
RunPE implementation with multiple evasive techniques (2)

RunPE implementation with multiple evasive techniques (2)

Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

Centralize Management of Intrusion Detection System like Suricata Bro Ossec ...

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

Fuzz 401/403/404 pages for bypasses

Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONLY.

Cobalt Strike C2 Reverse proxy that fends off Blue Teams, AVs, EDRs, scanners through packet inspection and malleable profile correlation

PoCs and tools for investigation of Windows process execution techniques

A slightly more fun way to disable windows defender + firewall. (through the WSC api)

A small x64 library to load dll's into memory.

A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs

LimeRAT | Simple, yet powerful remote administration tool for Windows (RAT)

A ModSecurity ruleset for detecting potential attacks using CVE-2018-6389

A vulnerable driver exploited by me (BYOVD) that is capable of terminating several EDRs and antivirus software in the market, rendering them…