25 results found Sort:

263
1.6k
other
35
Template-Driven AV/EDR Evasion Framework
Created 2021-08-02
58 commits to main branch, last one about a year ago
Awesome EDR Bypass Resources For Ethical Hacking
Created 2023-04-19
19 commits to main branch, last one 22 days ago
116
684
apache-2.0
21
A Highly capable Pe Packer
Created 2022-10-12
16 commits to main branch, last one 2 years ago
Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".
Created 2023-04-30
1,148 commits to main branch, last one 10 months ago
Automated DLL Sideloading Tool With EDR Evasion Capabilities
Created 2023-05-15
94 commits to main branch, last one 11 months ago
Materials for the workshop "Red Team Ops: Havoc 101"
Created 2023-02-17
123 commits to main branch, last one about a month ago
34
307
mit
6
indirect syscalls for AV/EDR evasion in Go assembly
Created 2023-04-07
68 commits to main branch, last one about a year ago
53
268
gpl-3.0
18
Multilayered AV/EDR Evasion Framework
Created 2024-05-26
138 commits to main branch, last one 3 months ago
Abusing Windows fork API and OneDrive.exe process to inject the malicious shellcode without allocating new RWX memory region.
Created 2024-05-24
6 commits to main branch, last one 6 months ago
This POC gives you the possibility to compile a .exe to completely avoid statically detection by AV/EPP/EDR of your C2-shellcode and download and execute your C2-shellcode which is hosted on your (C2)...
Created 2022-03-27
34 commits to main branch, last one about a year ago
40
204
unknown
5
"AMSI WRITE RAID" Vulnerability that leads to an effective AMSI BYPASS
Created 2024-05-03
11 commits to main branch, last one about a month ago
Use hardware breakpoints to spoof the call stack for both syscalls and API calls
Created 2023-03-03
4 commits to main branch, last one 6 months ago
40
173
unknown
5
A C2 framework for initial access in Go
Created 2021-07-16
345 commits to master branch, last one 2 years ago
The following two code samples can be used to understand the difference between direct syscalls and indirect syscalls
Created 2023-05-23
10 commits to main branch, last one 10 months ago
15
133
unknown
4
Small PoC of using a Microsoft signed executable as a lolbin.
Created 2023-02-27
2 commits to main branch, last one about a year ago
Start with shellcode execution using Windows APIs (high level), move on to native APIs (medium level) and finally to direct syscalls (low level).
Created 2023-04-14
17 commits to main branch, last one about a year ago
15
118
unknown
1
Artificially inflate a given binary to exceed common EDR file size limits. Can be used to bypass common EDR.
Created 2022-04-08
5 commits to main branch, last one 2 years ago
Evade EDR's the simple way, by not touching any of the API's they hook.
Created 2024-04-28
17 commits to main branch, last one 4 months ago
silence file system monitoring components by hooking their minifilters
Created 2023-10-30
44 commits to main branch, last one 10 months ago
This code example allows you to create a malware.exe sample that can be run in the context of a system service, and could be used for local privilege escalation in the context of an unquoted service p...
Created 2023-05-08
12 commits to main branch, last one about a year ago
6
50
apache-2.0
4
frida based script which automates the process of discovering and exploiting DLL Hijacks in target binaries. The discovered binaries can later be weaponized during Red Team Operations to evade AV/EDR'...
Created 2023-03-23
4 commits to main branch, last one about a year ago
Hidedump:a lsassdump tools that may bypass EDR
Created 2024-05-23
3 commits to main branch, last one 6 months ago
PowerJoker is a Dynamic PowerShell Reverse-Shell Generator; Unique Payloads with different results on Each Execution.
Created 2023-03-17
30 commits to main branch, last one 7 months ago
A WIP shellcode loader tool which bypasses AV/EDR, coded in C++, and equipped with a minimal console builder.
Created 2024-08-16
27 commits to main branch, last one 3 months ago