
SilentButDeadly
SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using…

SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using…

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

👁🗨 This script will simulate fake processes of analysis sandbox/VM software that some malware will try to avoid.

WePWNise generates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and…

CVE-2019-13498

Permanently disable EDRs as local admin

Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compatible with…

Hands-on red-team obfuscation workshop teaching AMSI bypass, ETW evasion, and payload obfuscation with PowerShell, Visual Basic, and C# to evade…

C++ shellcode injection technique using XOR encryption and UUID string conversion to bypass Windows Defender, with function call obfuscation and…

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

Mutates signed Windows binaries to retain valid catalog signatures while changing file hashes, bypassing hash-based endpoint blocks and exposing…

C-based PoC to bypass Windows PayloadRestrictions.dll and wdeg ROP mitigation, enabling payload execution and binary exploitation for security…

A slightly more fun way to disable windows defender + firewall. (through the WSC api)

Tools and PoCs for Windows syscall investigation.

Unfixed Windows PowerShell Filename Code Execution POC

C++ tool that patches Windows API calls to bypass sandbox RAM size checks, enabling malware to evade detection in isolated analysis environments.

PoC for generating bthprops.cpl module designed to be loaded by Fsquirt.exe LOLBin

A Zeek package to detect CVE-2022-23270, a PPTP vulnerability in Windows.