
obex
Obex – Blocking unwanted DLLs in user mode

Obex – Blocking unwanted DLLs in user mode

Apply a divide and conquer approach to bypass EDRs

More examples using the Impacket library designed for learning purposes.


A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.


DarkAgent Remote Administration Tool RAT by DragonHunter

POC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY

Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.

ARTi-C2 is a post-exploitation framework used to execute Atomic Red Team test cases with rapid payload deployment and execution capabilities via…


BOF combination of KillDefender and Backstab

Rust-based PoC using Windows fibers to execute in-memory code stealthily, hiding payload stacks from EDR by switching between control and payload…

A C# tool to output crackable DPAPI hashes from user MasterKeys

Proof-of-concept tool leveraging WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries, enabling EDR bypass for…

Infect Shared Files In Memory for Lateral Movement

Linux post exploitation privilege escalation enumeration

DLL Password Filter Implant with Exfiltration Capabilities