
Cronos
PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

Minimal proof-of-concept remote access trojan in Go using libp2p rendezvous and pubsub for self-healing command-and-control over Linux and Windows…

PowerShell-based RAT using WMI for remote command execution, lateral movement, and C2 communication. Enables file operations, process management,…

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

Using CVE-2023-21768 to manual map kernel mode driver

A Bind Shell Using the Fax Service and a DLL Hijack

Python framework for generating polymorphic Windows executables with multi-layer RC4 encryption, junkcode injection, and binary metadata spoofing to…

DCOM-based privilege escalation tool for Windows Server 2012-2022 and Windows 8-11, elevating users with ImpersonatePrivilege to NT AUTHORITY\SYSTEM…

Rust-based PoC using Windows fibers to execute in-memory code stealthily, hiding payload stacks from EDR by switching between control and payload…

a tool to manipulate dcc(domain cached credentials) in windows registry, based mainly on the work of mimikatz and impacket

Electron-based Android RAT with server-side control panel and client-side backdoor APK generator for remote device administration and penetration…