
NTDLLReflection
Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

different ntdll unhooking techniques : unhooking ntdll from disk, from KnownDlls, from suspended process, from remote server (fileless)

This repo contains : simple shellcode Loader , Encoders (base64 - custom - UUID - IPv4 - MAC), Encryptors (AES), Fileless Loader (Winhttp, socket)

Improved version of EKKO by @5pider that Encrypts only Image Sections

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

A collection of techniques, examples and a little bit of theory for manually obfuscating PowerShell scripts to achieve AV evasion, compiled for…

yet another sleep encryption thing. also used the default github repo name for this one.

FireProx written in Go

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

A simple BOF that frees UDRLs

kill anti-malware protected processes ( BYOVD )

Windows x64 Ring 0 rootkit enabling DKOM process hiding, privilege elevation, driver swapping, and anti-malware evasion by redirecting file…

Educational deep dive into macOS app bundles, plist files, and launchd process behavior, with offensive security notes on packaging payloads as .app…

Performing Indirect Clean Syscalls

DNS over HTTPS targeted malware (only runs once)

Bypass the Event Trace Windows(ETW) and unhook ntdll.

Amsi Bypass payload that works on Windwos 11