
CVE-2025-24813
Instructions for rapid deployment of Tomcat v9.0.90 with java 25.0.1 2025-10-21 LTS on Windows Server 2019 Standard for lazy researchers.

Instructions for rapid deployment of Tomcat v9.0.90 with java 25.0.1 2025-10-21 LTS on Windows Server 2019 Standard for lazy researchers.

LoadLibrary for offensive operations

Curated collection of EDR bypass resources including PoCs, tools, workshops, presentations, and blogs for ethical hacking and red team operations.

Create fake certs for binaries using windows binaries and the power of bat files

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

A proof of concept for abusing exception handlers to hook and bypass user mode EDR hooks.

DropEngine provides a malleable framework for creating shellcode runners, allowing operators to choose from a selection of components and combine…

Educational exploit for CVE-2022-30190 (Follina) demonstrating MSDT remote code execution via malicious Office documents, with detection and…

Windows CLFS LPE exploit PoC for security research

A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.

BlackLotus UEFI Windows Bootkit

Dynamic Windows API resolver and unhooker that detects and restores hooked functions (IAT, EAT, inline patches) to invoke unmonitored system calls…

Header-only Windows x64 indirect syscall library. Zero CRT, zero IAT, VEH anti-BP, AMSI/ETW bypass, W^X memory, per-call dynamic stubs.

Shellcode injection technique. Given as C++ header, standalone Rust program or library.

This repo contains some Amsi Bypass methods i found on different Blog Posts.

AV/EDR evasion via direct system calls.

Hide your Powershell script in plain sight. Bypass all Powershell security features