
Ghost-In-The-Logs
Kernel-level tool to disable Sysmon and Windows Event Logging via driver-based hook injection, enabling stealthy post-exploitation operations on…

Kernel-level tool to disable Sysmon and Windows Event Logging via driver-based hook injection, enabling stealthy post-exploitation operations on…

Fully undetectable and evasive ransomware written in Rust, leveraging a BYOVD technique to disable AV/EDR solutions on the infected systems.

Proof-of-concept exploiting a weakness to disable the eBPF verifier, enabling arbitrary eBPF code execution for kernel-level privilege escalation.

Permanently disable EDRs as local admin

Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)

Use CVE-2026-43074 to disable SELinux on Android (Linux 6.6/6.12)

Proof-of-concept demonstrating methods to disable or bypass Windows Defender by hiding, locking, or protecting its folders, enabling persistence…

Proof-of-concept exploit and write-up for CVE-2020-14372, demonstrating Secure Boot bypass via malicious ACPI SSDT to disable kernel lockdown and…

Exploit for CVE-2022-20186 in Arm Mali kernel driver, achieving arbitrary kernel code execution from untrusted app domain to disable SELinux and gain…

Exploit for CVE-2022-46395, an Arm Mali kernel driver vulnerability, achieving arbitrary kernel code execution to disable SELinux and gain root on…

Exploit for CVE-2022-20186 in the Arm Mali kernel driver, achieving arbitrary kernel code execution to disable SELinux and gain root on Google Pixel…

A small powershell script to disable print spooler service using desired state configuration

Exploits to disable kernel lockdown via ACPI table injection, targeting Ubuntu 18.04 and mainline kernels with two distinct techniques.

BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609,…

AppLocker-Based EDR Neutralization

Demo project how to bypass the disable_functions security control of PHP on Linux

Proof-of-concept exploit for CVE-2026-22003 demonstrating Redis Lua sandbox escape via debug.sethook to execute arbitrary system commands.

POC VIDEO - https://youtu.be/hNzmkJj-ImM?si=NF0yoSL578rNy7wN