Evasion
A POC of a new “threadless” process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote processes.
heavily vectorized c++17 compile time string encryption.
LSASS memory dumper using direct system calls and API unhooking.
My shitty attempt at tampering with the callstack based on the work of namazso, SilentMoonWalk, and VulcanRaven
Bypassing UAC with SSPI Datagram Contexts
A list of python tools to help create an OPSEC-safe Cobalt Strike profile.
AddDefenderExclusions Beacon Object File
A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.
Cobalt Strike + Brute Ratel C4 Beacon Object File (BOF) Conversion of the Mockingjay Process Injection Technique
Utilizing hardware breakpoints to evade monitoring by Endpoint Detection and Response platforms
A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.
Remove AV/EDR Kernel ObRegisterCallbacks、CmRegisterCallback、MiniFilter Callback、PsSetCreateProcessNotifyRoutine Callback、PsSetCreateThreadNotifyRoutine Callback、PsSetLoadImageNotifyRoutine Callback...
Simple (relatively) things allowing you to dig a bit deeper than usual.
PoC Implementation of a fully dynamic call stack spoofer
A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)
Guaranteed compile-time string literal obfuscation header-only library for C++14
obfuscated any constant encryption in compile time on any platform
A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.
Use hardware breakpoint to dynamically change SSN in run-time
BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR
Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs
A collection of weird ways to execute unmanaged code in .NET
