
SysWhispers3
SysWhispers on Steroids - AV/EDR evasion via direct system calls.

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

Hide your Powershell script in plain sight. Bypass all Powershell security features

c++ fully undetected shellcode launcher ;)

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

Performing Indirect Clean Syscalls

A BOF that runs unmanaged PEs inline

HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Evasion kit for Cobalt Strike

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

Dynamically invoke arbitrary unmanaged code

C++ library that retrieves and spoofs Windows syscall arguments using hardware breakpoints and exception handlers to subvert EDR telemetry.

C++ self-Injecting dropper based on various EDR evasion techniques.

Rubber Ducky compatible clone based on CJMCU BadUSB HW.

Azure Function that validates and relays Cobalt Strike beacon traffic using malleable C2 profiles, redirecting invalid requests to a decoy site and…

Reflective x64 PE/DLL Loader implemented using Dynamic Indirect Syscalls

Trojanize your payload - WinRAR (SFX) automatization - under Linux distros