gmh5225/WatchDogKiller
PoC exploit for the vulnerable WatchDog Anti-Malware driver (amsdk.sys) – weaponized to kill protected EDR/AV processes via BYOVD.
Abusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes.
Appears on
Quick read
Latest capture 2026-07-30 03:03
0 paths
Agent instructions and tool configuration found in this repository.
No config files detected.
3 observed captures since 2026-06-24. Charts use measured snapshots only.
Stars from first capture 0
All tracked data
Observed snapshots
Observed snapshots
Nearest indexed repositories by embedding similarity.
PoC exploit for the vulnerable WatchDog Anti-Malware driver (amsdk.sys) – weaponized to kill protected EDR/AV processes via BYOVD.
A lib that allows using mhyprot2 driver for enum process modules, r/w process memory and kill process.
Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes
It's pointy and it hurts!
Proof of Concepts code for Bring Your Own Vulnerable Driver techniques
Me fockin' pe protector