
HyperDeceit
HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…


Ability to detect suspicious activity such as (WEP/WPA/WPS) attack by sniffing the air for wireless packets.

A sophisticated, wizard-driven Python exploit tool targeting CVE-2025-53770, a critical (CVSS 9.8) unauthenticated remote code execution (RCE)…

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

Adversary Emulation Framework

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).

Best DDoS Attack Script Python3, (Cyber / DDos) Attack With 56 Methods

ESP32DIV is a multi-purpose wireless offensive and defensive toolkit powered by an ESP32

Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.

:dart: Prevent RubberDucky (or other keystroke injection) attacks