

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Pingtunnel is a tool that send TCP/UDP traffic over ICMP

A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to evade…

ShadowNet is an anonymous routing protocol that forces all connections (system-wide) to go through Tor while implementing Mixnet-like…

Redirects EDR working folders using a Bind Filter (bindflt.sys) to bypass endpoint detection, corrupt EDR services, or replace with…

A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.

Now You See Me, Now You Don't

Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes, protect and elevate them with token manipulation.

Obex – Blocking unwanted DLLs in user mode

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully…

Spoilerwall introduces a brand new concept in the field of network hardening. Avoid being scanned by spoiling movies on all your ports!