
EDRception
A proof of concept for abusing exception handlers to hook and bypass user mode EDR hooks.

A proof of concept for abusing exception handlers to hook and bypass user mode EDR hooks.

Kernel-mode hook that intercepts, decrypts, and nullifies BEDaisy-to-service report traffic to suppress anti-cheat detection on UEFI and non-UEFI…

x64 Dynamic Reverse Engineering Toolkit

The first analysis framework for CPU microcode

Hardware breakpoint hooking engine for Windows that uses debug registers to hook functions, bypass ETW/AMSI, and evade user-land EDR monitoring.

Agent-based tool that collects OS, hardware, file, and hook data from internet-connected sandboxes via HTTPS exfiltration, aiding Red Team artifact…

C++ DLL that performs Import Address Table hooking by parsing PE headers and redirecting imported function addresses to a custom hook inside a target…

Proof of Concept for WatchGuard Authenticated Arbitrary File Read (CVE-2022-31749)

an iOS kernel function hooking framework for checkra1n'able devices


exp for CVE-2019-0887

Hook PasswordChangeNotify

Exploit for CVE-2020-6514 targeting WebRTC SCTP memory corruption in Android applications. Uses Frida to hook native functions and alter SCTP packets…

Exploit for Gogs RCE (CVE-2018-18925) leveraging session forgery and Git hook injection to achieve arbitrary command execution with root privileges.

Kernel-level tool to disable Sysmon and Windows Event Logging via driver-based hook injection, enabling stealthy post-exploitation operations on…

A set of scripts that ease working with frida

GO sandbox to run untrusted code

CERIO RCE CVE-2018-18852, authenticated (vendor defaults) web-based RCE as root user.