
TangledWinExec
PoCs and tools for investigation of Windows process execution techniques

PoCs and tools for investigation of Windows process execution techniques

Curated reading list and taxonomy of attack and defense research for mobile on-device AI systems, covering adversarial, backdoor, model stealing, and…

reverse engineering Gemini's SynthID detection

Lifetime AMSI bypass

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Tools and PoCs for Windows syscall investigation.

Signtool for expired certificates

Hands-on DEFCON workshop materials for killing and silencing EDR agents: lab setup, BYOVD, custom C/C++ evasion tooling, and reverse engineering.

Windows 11 24H2-25H2 Runtime PatchGuard Bypass

Mutates signed Windows binaries to retain valid catalog signatures while changing file hashes, bypassing hash-based endpoint blocks and exposing…

Anti-LLM obfuscation via finger counting

reverse engineering SynthID for text

Create Anti-Copy DRM Malware

Different methods to detect a virtualized environment or potential debugging

Scalable assembly analysis platform for indexing, clone search, and executable classification using static, dynamic, and machine-learning techniques…

Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

Evaluation framework for studying LLM agents that automatically generate working exploits from vulnerability reports, bypassing modern security…

Technical webinars on reverse engineering, malware analysis, and software protection.