
Chaos-Rootkit
Windows x64 Ring 0 rootkit enabling DKOM process hiding, privilege elevation, driver swapping, and anti-malware evasion by redirecting file…

Windows x64 Ring 0 rootkit enabling DKOM process hiding, privilege elevation, driver swapping, and anti-malware evasion by redirecting file…

HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.

AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

A sophisticated, covert Windows-based credential dumper using C++ and MASM x64.

Powershell reverse shell using HTTP/S protocol with AMSI bypass and Proxy Aware

RedSails is a Python based post-exploitation project aimed at bypassing host based security monitoring and logging. DerbyCon 2017 Talk:…

Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths

.NET assembly loader with patchless AMSI and ETW bypass

Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using…

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

Apply a divide and conquer approach to bypass EDRs

Patch AMSI and ETW

Single stub direct and indirect syscalling with runtime SSN resolving for windows.