
EDR-Freeze
EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

👁🗨 This script will simulate fake processes of analysis sandbox/VM software that some malware will try to avoid.

SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using…

:dart: Prevent RubberDucky (or other keystroke injection) attacks

Run PowerShell with rundll32. Bypass software restrictions.

An anti-ARP-spoofing application software that use active and passive scanning methods to detect and remove any ARP-spoofer from the network.


WePWNise generates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and…

Tunnel IPv4 data through DNS servers to bypass firewall restrictions and provide covert network access for penetration testing.


A vulnerable driver exploited by me (BYOVD) that is capable of terminating several EDRs and antivirus software in the market, rendering them…

CVE-2019-13498

Reverse Engineer of Trust Decision Chinese Security

Run Powershell without software restrictions.

This is a proof-of-concept of malicious software running inside of ModSecurity WAF.

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…