Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET assemblies. it works with a multi-layer confidence model that dramatically reduce the false positive rate and hunt for malicious behaviour.
☆67Jul 5, 2026Updated 2 months ago
Alternatives and similar repositories for aether
Users that are interested in aether are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.☆90Jun 15, 2026Updated 3 months ago
- Modern Web Application Firewall for Kong Gateway☆30Updated this week
- Indicators of Normality☆11Jul 22, 2022Updated 4 years ago
- Proof-of-concept security demo illustrating how PowerShell can create trusted-looking Windows toast notifications chained together with C…☆18Apr 12, 2026Updated 5 months ago
- DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them agai…☆36Jul 28, 2026Updated 2 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆33May 19, 2026Updated 4 months ago
- Helps defenders find their WSUS configurations in the wake of CVE-2025-59287☆46Oct 28, 2025Updated 11 months ago
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.☆56Mar 30, 2026Updated 6 months ago
- Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID☆184Updated this week
- Async BOF that notifies the operator when a user connects to a local or remote target system.☆34Jul 30, 2026Updated 2 months ago
- This repository contains the research tool presented at x33fcon 2026, along with the associated presentation slides. The content is made …☆65Jun 15, 2026Updated 3 months ago
- Repo hacks☆21Jul 30, 2026Updated 2 months ago
- Evasive loader for .NET Framework assemblies☆84May 12, 2026Updated 4 months ago
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆26May 10, 2026Updated 4 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijac…☆161Jul 20, 2026Updated 2 months ago
- Sanctum is an experimental proof-of-concept EDR, designed to detect modern malware techniques, above and beyond the capabilities of antiv…☆567Mar 24, 2026Updated 6 months ago
- User-mode ETW interception and telemetry manipulation lab for Windows security research.☆44Jun 15, 2026Updated 3 months ago
- A compiled language for Windows position-independent x86-64 shellcode and Beacon Object Files.☆247Jun 28, 2026Updated 3 months ago
- Cross-platform incident response toolkit. 28 pre-built use cases in a single zero-install binary: triage, threat hunting, memory forensic…☆157Jul 28, 2026Updated 2 months ago
- Repository hosting a hypothetical EDR Spoofer, as discovered originally by Nightmare-Eclipse☆43May 27, 2026Updated 4 months ago
- KslDump — Why bring your own knife when Defender already left one in the kitchen?☆415Apr 13, 2026Updated 5 months ago
- Microsoft Vulnerable Driver Block Lists in CSV and JSON for SIEM lookups☆55Sep 15, 2026Updated 2 weeks ago
- Janus analyzes C2 telemetry to surface failure patterns, operator friction, and automation opportunities across engagements.☆59Jun 23, 2026Updated 3 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A small set of Beacon Object Files (BOFs) that I developed over the time with a Magic: The Gathering theme.☆22Jul 15, 2025Updated last year
- A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike☆244Apr 11, 2026Updated 5 months ago
- 🕵️ Real-time desktop surveillance over HTTP - DXGI capture, MJPEG stream, single C binary, zero dependencies. Built for red teams with n…☆23Jul 28, 2026Updated 2 months ago
- Command Augmentation support for BOFs and .NET assemblies across agents☆52Jul 30, 2026Updated 2 months ago
- Test bench lab for Shellcode Obfuscation☆38Sep 2, 2025Updated last year
- A collection of PoCs to do common things in unconventional ways☆121Aug 31, 2025Updated last year
- ☆24Sep 9, 2025Updated last year
- Comprehensive Windows Syscall Extraction & Analysis Framework☆171Aug 30, 2025Updated last year
- Phantom is project created to perform loading and executing unmanaged code in memory within an IIS environment running in full‑trust mode…☆107Jun 5, 2026Updated 3 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A Beacon Object File (BOF) for Havoc/CS to Bypass PPL and Dump Lsass☆178Sep 22, 2025Updated last year
- Remote DLL Injection with Timer-based Shellcode Execution☆215Jul 18, 2025Updated last year
- A Crystal Palace shared library to resolve & perform syscalls☆66Oct 29, 2025Updated 11 months ago
- Windows memory scanner for call stack spoofing detection, unbacked shellcode, injected DLLs and in-memory C2 implants.☆39May 22, 2026Updated 4 months ago
- Sleep obfuscation☆275Dec 13, 2024Updated last year
- Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods…☆205Apr 27, 2026Updated 5 months ago
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆29May 21, 2026Updated 4 months ago