
RefleXXion
RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, it first…

RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, it first…

An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer

CVE-2020-1048 bypass: binary planting PoC

Analysis and exploitation of CVE-2025-4275 (Hydr0ph0bia), a Secure Boot trust-chain weakness where firmware variables are used to introduce…

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

PowerShell tool for red teamers that clears execution evidence by stopping event logging, removing file and registry artifacts, and saving timestamps…

PoC for generating bthprops.cpl module designed to be loaded by Fsquirt.exe LOLBin

Repository hosting a hypothetical EDR Spoofer, as discovered originally by Nightmare-Eclipse

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Generate Payloads and Control Remote Machines. [Discontinued]

Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths

A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation

HP Slate 7 2800 Android 4.1.1 rooting kit using CVE-2015-1805.

A slightly more fun way to disable windows defender + firewall. (through the WSC api)