
Crystal-Loaders
A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike

A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike

Redirects EDR working folders using a Bind Filter (bindflt.sys) to bypass endpoint detection, corrupt EDR services, or replace with…

Reverse shell that can bypass windows defender detection

Offensive Lua.



Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel space

Permanently disable EDRs as local admin

Remove API hooks from a Beacon process.

Indirect syscalls + DInvoke made simple.

Lists of AMSI triggers (VBA, JScript / VBScript)

LSTAR - CobaltStrike Translated to EN

Header-only Windows x64 indirect syscall library. Zero CRT, zero IAT, VEH anti-BP, AMSI/ETW bypass, W^X memory, per-call dynamic stubs.

UDRL for CS

Revenant - A 3rd party agent for Havoc that demonstrates evasion techniques in the context of a C2 framework

RunPE implementation with multiple evasive techniques (2)

A slightly more fun way to disable windows defender + firewall. (through the WSC api)