
Dirty-Vanity
A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

C# obfuscator that bypass windows defender

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

Inject DLLs into the explorer process using icons

Tools and PoCs for Windows syscall investigation.

Amsi Bypass payload that works on Windwos 11

macOS Initial Access Payload Generator

C# Reflective loader for unmanaged binaries.

Call stack spoofing for Rust

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime

A delicious, but malicious SSL-VPN server 🌮

Hides reflective payloads in GPU memory via CUDA APIs, wiping host memory during sleep and using a VEH handler to restore executable memory, evading…

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

Attempt at Obfuscated version of SharpCollection

Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap

A PoC ransomware sample to test out your ransomware response strategy.