
TitanHide
Windows kernel driver that hooks Nt* SSDT functions to hide debuggers and processes from anti-debug checks, with an x64dbg plugin for stealth…

Windows kernel driver that hooks Nt* SSDT functions to hide debuggers and processes from anti-debug checks, with an x64dbg plugin for stealth…

A PoC on how to use a Compute Shader as Payload

Python-based keylogger for capturing and logging keystrokes. Designed for educational security research and testing.

A curated list of Android Security materials and resources For Pentesters and Bug Hunters

Super elite end-to-end implant 0day. Full kill-chain. Exploit, escalate, pivot, poison, persistence.

WinDbg plugin for automated malware dynamic analysis and IOC extraction. Executes within the debugger to collect predefined indicators and writes…

A list of covert channels and steganography/steganalysis resources (books, papers & tools)


A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

Proof-of-concept tool for detecting AMSI (Antimalware Scan Interface) bypasses and malicious in-memory script activity on Windows endpoints.

How to use PiDqSerializationWrite. Introduces how to safely read and write from mapped driver

POC about how to detect windows kernel debug by pool tag.

Cortex: a Powerful Observable Analysis and Active Response Engine

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

A tutorial on how to write a packer for Windows!

PoC demonstrating SHA-1 code signing forgery and missing High Entropy ASLR in CyberGhostVPN installer, enabling trust bypass and predictable memory…