
EDR-Freeze
EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

PoCs and tools for investigation of Windows process execution techniques

Red-team EDR evasion utility that terminates security services by abusing Process Explorer driver functionality to bypass PPL and ObRegisterCallbacks.

Windows x64 kernel mode rootkit process hollowing POC.

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

CVE-2025-61155 — arbitrary process termination in GameDriverX64.sys (Tower of Fantasy anti-cheat). Original IDA Pro teardown, PoC, YARA, IOCs,…

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Stealth Windows process enumeration PoC that lists PIDs using NTFS via NtQueryInformationFile, bypassing standard monitoring APIs and enabling EDR…

Test cases for broken MIME and tools to generate and process these

Venom is a library that meant to perform evasive communication using stolen browser socket

👁🗨 This script will simulate fake processes of analysis sandbox/VM software that some malware will try to avoid.