


Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)

Offensive Lua.

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

A BOF that runs unmanaged PEs inline

C++ self-Injecting dropper based on various EDR evasion techniques.

Reflective x64 PE/DLL Loader implemented using Dynamic Indirect Syscalls

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Exploitation of echo_driver.sys

Source generator to add D/Invoke and indirect syscall methods to a C# project.

Execute shellcode files with rundll32



Indirect syscalls + DInvoke made simple.

IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then reflective load…

A sophisticated, covert Windows-based credential dumper using C++ and MASM x64.

Dynamically invoke arbitrary unmanaged code