
AntiDebug-AntiVM
Different methods to detect a virtualized environment or potential debugging

Different methods to detect a virtualized environment or potential debugging

Red team tool for EDR evasion: dynamically resolves syscall IDs, patches ntdll stubs, unhooks IAT hooks, and lists hooked APIs from major EDR vendors.

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Signtool for expired certificates

Create Anti-Copy DRM Malware

Lists of AMSI triggers (VBA, JScript / VBScript)

Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors


reverse engineering Gemini's SynthID detection

Comprehensive red teaming notes covering offensive security techniques including code injection, defense evasion, lateral movement, and persistence,…

Intel Pin-based tracer for API calls, syscalls, and instructions with anti-debug evasion, used for malware analysis and reverse engineering of packed…