-
NetRunner Public
Forked from eversinc33/NetRunnerA .NET assembly tracer using Harmony for runtime method interception.
C# UpdatedOct 24, 2025 -
-
kernel-callback-removal Public
Forked from V-i-x-x/kernel-callback-removalkernel callback removal (Bypassing EDR Detections)
C++ UpdatedMar 21, 2025 -
CVE-2025-21333-POC-driver-exploit Public
Forked from MrAle98/CVE-2025-21333-POCPOC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY
-
vxlang-page Public
Forked from vxlang/vxlang-pageprotector & obfuscator & code virtualizer
C++ UpdatedFeb 27, 2025 -
-
HookGuard Public
Forked from SamuelTulach/HookGuardHooking Windows' exception dispatcher to protect process's PML4
C UpdatedJan 24, 2025 -
rootkit-blackpill Public
Forked from shard77/blackpillA Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs
Rust GNU General Public License v3.0 UpdatedJan 10, 2025 -
EDRPrison Public
Forked from senzee1984/EDRPrisonLeverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry
C# UpdatedAug 2, 2024 -
EDRSilencer Public
Forked from netero1010/EDRSilencerA tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.
C MIT License UpdatedJun 28, 2024 -
-
GoodKit Public
Forked from SilverPlate3/GoodKitRootkit for the blue team. Sophisticated and optimized LKM to detect and prevent malicious activity
C++ UpdatedApr 26, 2024 -
24h2-nt-exploit Public
Forked from exploits-forsale/24h2-nt-exploitExploit targeting NT kernel in 24H2 Windows Insider Preview
C MIT License UpdatedApr 26, 2024 -
winafl Public
Forked from googleprojectzero/winaflA fork of AFL for fuzzing Windows binaries
C Apache License 2.0 UpdatedApr 10, 2024 -
TripleCrossEbpfRootkit Public
Forked from h3xduck/TripleCrossA Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.
C GNU General Public License v3.0 UpdatedApr 7, 2024 -
Nidhogg_Rootkit Public
Forked from Idov31/NidhoggNidhogg is an all-in-one simple to use rootkit.
C++ GNU General Public License v3.0 UpdatedMar 16, 2024 -
InflativeLoading Public
Forked from senzee1984/InflativeLoadingDynamically convert a native EXE to PIC shellcode by prepending a shellcode stub
Python UpdatedMar 8, 2024 -
VX-API Public
Forked from vxunderground/VX-APICollection of various malicious functionality to aid in malware development
C++ MIT License UpdatedFeb 28, 2024 -
EDR-Preloader Public
Forked from MalwareTech/EDR-PreloaderAn EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer
C++ UpdatedFeb 13, 2024 -
-
Stardust Public
Forked from Cracked5pider/StardustA modern 64-bit position independent implant template
C UpdatedJan 27, 2024 -
LOLSpoof Public
Forked from itaymigdal/LOLSpoofAn interactive shell to spoof some LOLBins command line
Nim UpdatedJan 19, 2024 -
llvm-yx-callobfuscator Public
Forked from janoglezcampos/llvm-yx-callobfuscatorLLVM plugin to transparently apply stack spoofing and indirect syscalls to Windows x64 native calls at compile time.
C GNU General Public License v3.0 UpdatedJan 17, 2024 -
EDRNoiseMaker Public
Forked from amjcyber/EDRNoiseMakerDetect WFP filters blocking EDR communications
PowerShell GNU General Public License v3.0 UpdatedJan 5, 2024 -
Stinger Public
Forked from hackerhouse-opensource/StingerCIA UAC bypass implementation of Stinger that obtains the token from an auto-elevated process, modifies it, and reuses it to execute as Administrator.
C++ UpdatedJan 3, 2024 -
EDRception Public
Forked from MalwareTech/EDRceptionA proof of concept for abusing exception handlers to hook and bypass user mode EDR hooks.
C++ UpdatedDec 27, 2023 -
PoolParty Public
Forked from SafeBreach-Labs/PoolPartyA set of fully-undetectable process injection techniques abusing Windows Thread Pools
C++ BSD 3-Clause "New" or "Revised" License UpdatedDec 11, 2023 -
BestEdrOfTheMarket Public
Forked from Xacone/BestEdrOfTheMarketLittle AV/EDR bypassing lab for training & learning purposes
C++ UpdatedDec 4, 2023 -
Black-Angel-Rootkit Public
Forked from XaFF-XaFF/Black-Angel-RootkitBlack Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled DSE while maintaining its full functionality.
C++ GNU General Public License v3.0 UpdatedNov 9, 2023 -
VDR Public
Forked from TakahiroHaruyama/VDRVulnerable driver research tool, result and exploit PoCs
Python GNU General Public License v3.0 UpdatedNov 1, 2023