
blindsight
Red teaming tool to dump LSASS memory, bypassing basic countermeasures.

Red teaming tool to dump LSASS memory, bypassing basic countermeasures.

This tool demonstrates the application of fundamental physics discoveries to cybersecurity.

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).

evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)

Generate Payloads and Control Remote Machines. [Discontinued]

Memory API proxy via signed mozglue.dll

Reflective PE packer.

ThrottleStop.sys Arbitrary Physical Memory R/W


CitrixBleed-2 (CVE-2025-5777) – proof-of-concept exploit for NetScaler ADC/Gateway “memory bleed”

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.