This is your work, valued
Red Team Dev
ModuleStomped. Proof of concept to detect module stomping detection by looking for modified .pdata sections.
41cet-spoofing-detection. Stack spoofing Detection for CET processes by comparing shadow and user stacks.
39vehspoof. Callstack spoofing using a VEH because VEH all the things.
24static-nmap. Statically compiled nmap with scripting
13taskpwn. Remote Task Scheduler Enumeration
13jbstrike. A Small, Simple C2. Designed to be lightweight.
9httpdropper. Simple HTTP Shellcode dropper, designed only to defeat defender
9EyYoEtwWhereYouAt. Correlating kernel notifications with the lack of ETW events to detect ETW Patching
7Amsi-Patch. AMSI ScanBuffer Patch with API Hook poc
6SuspiciousThreads. A Poc attempt at hunting suspicious thread creation events using ETW only.
50xjbb.
1NetExec. The Network Execution Tool
1http. Simple HTTP File server with upload support for pen-testing CTFs
1indirect-syscalls. Indirect Syscall implementation, nothing new.
1wde-bypass. Windows Defender Anti Virus Emulator Bypasses
1