This is your work, valued
wanna be a red team ninja
Killer. Killer is a super simple tool designed to bypass AV/EDR security tools using various evasive techniques and used by Patchwork group.
846HuffLoader. Huffman Coding in Shellcode Obfuscation & Dynamic Indirect Syscalls Loader.
290KernelCallbackTable-Injection-PoC. Proof of Concept for manipulating the Kernel Callback Table in the Process Environment Block (PEB) to perform process injection and hijack execution flow.
275UnCanny. Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin resolution experiments
87APT-Attack-Simulation. Projected developed for fun only that simulates APT 29 and Lockbit TTPs, showcasing phishing, ISO execution, and DLL proxying for persistence and privilege escalation.
63ShellHWEventExec. BOF and research notes from hunting execution paths, covering Shell.HWEventHandlerShellExecute COM execution through the AutoPlay IHWEventHandler flow + ssh-shellhost.exe direct PTY command execution behavior.
38UNCagedSandbox. Research on a new PoC for a Windows Sandbox .wsb HostFolder UNC path primitive that causes the host to authenticate over SMB and leak NetNTLMv2 before the sandbox session is fully initialized.
31InviGuard. Basic network sec tool for real-time threat detection and C2 communication prevention. Features 70+ detection modules, IOC integration, customizable alerts, and a dashboard with analytics. API-ready for seamless security solution integration.
17awesome-injection. Just contributing here :) --- Centralized resource for listing and organizing known injection techniques and POCs
2