31 results found Sort:

270
1.7k
other
36
Template-Driven AV/EDR Evasion Framework
Created 2021-08-02
58 commits to main branch, last one about a year ago
119
1.2k
unknown
29
Awesome EDR Bypass Resources For Ethical Hacking
Created 2023-04-19
22 commits to main branch, last one 2 months ago
119
698
apache-2.0
21
A Highly capable Pe Packer
Created 2022-10-12
16 commits to main branch, last one 2 years ago
Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".
Created 2023-04-30
1,148 commits to main branch, last one about a year ago
104
621
gpl-3.0
26
Multilayered AV/EDR Evasion Framework
Created 2024-05-26
166 commits to main branch, last one a day ago
Automated DLL Sideloading Tool With EDR Evasion Capabilities
Created 2023-05-15
94 commits to main branch, last one about a year ago
Materials for the workshop "Red Team Ops: Havoc 101"
Created 2023-02-17
123 commits to main branch, last one 6 months ago
39
326
mit
6
indirect syscalls for AV/EDR evasion in Go assembly
Created 2023-04-07
68 commits to main branch, last one 2 years ago
Abusing Windows fork API and OneDrive.exe process to inject the malicious shellcode without allocating new RWX memory region.
Created 2024-05-24
6 commits to main branch, last one 11 months ago
47
272
unknown
5
"AMSI WRITE RAID" Vulnerability that leads to an effective AMSI BYPASS
Created 2024-05-03
24 commits to main branch, last one 15 days ago
This POC gives you the possibility to compile a .exe to completely avoid statically detection by AV/EPP/EDR of your C2-shellcode and download and execute your C2-shellcode which is hosted on your (C2)...
Created 2022-03-27
34 commits to main branch, last one about a year ago
Use hardware breakpoints to spoof the call stack for both syscalls and API calls
Created 2023-03-03
4 commits to main branch, last one 10 months ago
The following two code samples can be used to understand the difference between direct syscalls and indirect syscalls
Created 2023-05-23
10 commits to main branch, last one about a year ago
39
180
unknown
6
A C2 framework for initial access in Go
Created 2021-07-16
345 commits to master branch, last one 2 years ago
kernel callback removal (Bypassing EDR Detections)
Created 2025-03-18
24 commits to main branch, last one about a month ago
16
137
unknown
4
Small PoC of using a Microsoft signed executable as a lolbin.
Created 2023-02-27
2 commits to main branch, last one 2 years ago
Start with shellcode execution using Windows APIs (high level), move on to native APIs (medium level) and finally to direct syscalls (low level).
Created 2023-04-14
17 commits to main branch, last one about a year ago
15
120
unknown
1
Artificially inflate a given binary to exceed common EDR file size limits. Can be used to bypass common EDR.
Created 2022-04-08
5 commits to main branch, last one 3 years ago
20
104
unknown
3
Malleable shellcode loader written in C and Assembly utilizing direct or indirect syscalls for evading EDR hooks
Created 2024-12-15
1 commits to main branch, last one 4 months ago
Evade EDR's the simple way, by not touching any of the API's they hook.
Created 2024-04-28
18 commits to main branch, last one 2 months ago
silence file system monitoring components by hooking their minifilters
Created 2023-10-30
44 commits to main branch, last one about a year ago
PowerJoker is a Python program which generate a Dynamic PowerShell Reverse-Shell Generator; Unique Payloads with different results on Each Execution.
Created 2023-03-17
35 commits to main branch, last one 3 months ago
This code example allows you to create a malware.exe sample that can be run in the context of a system service, and could be used for local privilege escalation in the context of an unquoted service p...
Created 2023-05-08
12 commits to main branch, last one about a year ago
6
51
apache-2.0
4
frida based script which automates the process of discovering and exploiting DLL Hijacks in target binaries. The discovered binaries can later be weaponized during Red Team Operations to evade AV/EDR'...
Created 2023-03-23
4 commits to main branch, last one 2 years ago
Hidedump:a lsassdump tools that may bypass EDR
Created 2024-05-23
3 commits to main branch, last one 11 months ago
A WIP shellcode loader tool which bypasses AV/EDR, coded in C++, and equipped with a minimal console builder.
Created 2024-08-16
29 commits to main branch, last one a day ago
Rust malware EDR evasion via direct syscalls, fully implemented as an example in Rust
Created 2024-05-18
29 commits to master branch, last one 10 months ago
Repository of scripts from my blog post on bypassing the YARA rule Windows_Trojan_CobaltStrike_f0b627fc by generating alternative shellcode sequences.
Created 2024-10-16
6 commits to main branch, last one 6 months ago
10
32
apache-2.0
2
A Blind EDR Project for Educational Purposes
Created 2025-01-07
12 commits to master branch, last one 3 months ago