
swarmer
A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN

A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN

Redirects EDR working folders using a Bind Filter (bindflt.sys) to bypass endpoint detection, corrupt EDR services, or replace with…

A PoC exploit for CVE-2022-41622 - a CSRF in F5 BIG-IP control plane that leads to remote root

Now You See Me, Now You Don't

Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes, protect and elevate them with token manipulation.

Demonstrates CVE-2022-34303 Secure Boot bypass via CryptoPro signed UEFI Shell, using the mm command to nullify gSecurity2 and load unsigned UEFI…

Demonstrates CVE-2022-34301 Secure Boot bypass via Eurosoft signed UEFI Shell (esdiags.efi), using the mm command to nullify gSecurity2 and load…

PostShell - Post Exploitation Bind/Backconnect Shell

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Sigma detection rules for AI agent security monitoring

Demonstrates CVE-2022-34302, a Secure Boot bypass via the New Horizon Datasys signed bootloader whose built-in custom PE/COFF loader executes…