
GhostDriver
yet another AV killer tool using BYOVD

yet another AV killer tool using BYOVD

Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.

This repo covers some code execution and AV Evasion methods for Macros in Office documents

Activation Context Hijacking Evasion Tool

UEFI rootkit under development focusing on privilege escalation, C2 integration, and anti-EDR/AV evasion for real-world malware deployment.

Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.


Miscellaneous exploit code

Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.

Exploit for CVE-2021-3156 (Baron Samedit), a heap-based buffer overflow in sudo, enabling local privilege escalation. Includes target list and…

Automated Linux evil maid attack

UAC bypass for x64 Windows 7 - 11

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin…

A Bind Shell Using the Fax Service and a DLL Hijack

A tool to transform Chromium browsers into a C2 Implant

PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…