A small script for auditing EDR telemetry. Zero-dependency, naked binaries on Linux and Windows generating raw x86_64 assembly syscalls to check user-mode API hooking bypasses.
High-fidelity TLS stealth engine. Built in Go, it utilizes uTLS to mimic modern browser fingerprints and performs ALPN stripping to bypass JA3/JA4 detection, also forcing HTTP/1.1 downgrades. Built for lead generation, WAF evasion testing, etc.