
RPC-Triage
A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

Different methods to detect a virtualized environment or potential debugging

Assortment of hashing algorithms used in malware

Imphash-like calculation on Golang binaries

PoCs and tools for investigation of Windows process execution techniques

Python library for parsing CLR/PE metadata in .NET assemblies, exposing streams and hash fingerprints to support malware analysis and threat hunting.

Tools and PoCs for Windows syscall investigation.

Mutates signed Windows binaries to retain valid catalog signatures while changing file hashes, bypassing hash-based endpoint blocks and exposing…

Lifetime AMSI bypass

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Signtool for expired certificates

A Binary Genetic Traits Lexer Framework

Create Anti-Copy DRM Malware

Windows 11 24H2-25H2 Runtime PatchGuard Bypass

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…

Research repository detailing exploitation techniques against Apple's Display Co-Processor (DCP), including firmware analysis and hardware-level…