
Terminator_Killer
Kernel-mode process killer exploiting CVE-2026-0828 (BYOVD) to terminate protected processes via a vulnerable signed driver, bypassing PPL and…

Kernel-mode process killer exploiting CVE-2026-0828 (BYOVD) to terminate protected processes via a vulnerable signed driver, bypassing PPL and…

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

👁🗨 This script will simulate fake processes of analysis sandbox/VM software that some malware will try to avoid.

Stealth Windows process enumeration PoC that lists PIDs using NTFS via NtQueryInformationFile, bypassing standard monitoring APIs and enabling EDR…

A rootkit for ubuntu-16.04.6 (Linux 4.4). Can hide a process, give root access and hide itself

Educational deep dive into macOS app bundles, plist files, and launchd process behavior, with offensive security notes on packaging payloads as .app…

SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using…

Venom is a library that meant to perform evasive communication using stolen browser socket

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)

C# Azure Function with an HTTP trigger that generates obfuscated PowerShell snippets that break or disable AMSI for the current process.

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…

Python-based crypter that encrypts source code with AES-256 and Base64, evades VM detection via registry, process, and MAC checks, and executes…

CVE-2025-61155 — arbitrary process termination in GameDriverX64.sys (Tower of Fantasy anti-cheat). Original IDA Pro teardown, PoC, YARA, IOCs,…

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

PoCs and tools for investigation of Windows process execution techniques

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…