Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET assemblies. it works with a multi-layer confidence model that dramatically reduce the false positive rate and hunt for malicious behaviour.
☆59Jul 5, 2026Updated 2 months ago
Alternatives and similar repositories for aether
Users that are interested in aether are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.☆91Jun 15, 2026Updated 2 months ago
- Modern Web Application Firewall for Kong Gateway☆28Updated this week
- ☆33May 19, 2026Updated 3 months ago
- DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them agai…☆36Jul 28, 2026Updated last month
- Indicators of Normality☆11Jul 22, 2022Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Proof-of-concept security demo illustrating how PowerShell can create trusted-looking Windows toast notifications chained together with C…☆18Apr 12, 2026Updated 5 months ago
- Helps defenders find their WSUS configurations in the wake of CVE-2025-59287☆46Oct 28, 2025Updated 10 months ago
- Async BOF that notifies the operator when a user connects to a local or remote target system.☆34Jul 30, 2026Updated last month
- Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID☆184Jul 10, 2026Updated 2 months ago
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.☆55Mar 30, 2026Updated 5 months ago
- Evasive loader for .NET Framework assemblies☆83May 12, 2026Updated 4 months ago
- User-mode ETW interception and telemetry manipulation lab for Windows security research.☆44Jun 15, 2026Updated 2 months ago
- Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijac…☆159Jul 20, 2026Updated last month
- This repository contains the research tool presented at x33fcon 2026, along with the associated presentation slides. The content is made …☆65Jun 15, 2026Updated 2 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Repo hacks☆21Jul 30, 2026Updated last month
- Repository hosting a hypothetical EDR Spoofer, as discovered originally by Nightmare-Eclipse☆43May 27, 2026Updated 3 months ago
- Janus analyzes C2 telemetry to surface failure patterns, operator friction, and automation opportunities across engagements.☆58Jun 23, 2026Updated 2 months ago
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆27May 10, 2026Updated 4 months ago
- Sanctum is an experimental proof-of-concept EDR, designed to detect modern malware techniques, above and beyond the capabilities of antiv…☆568Mar 24, 2026Updated 5 months ago
- A compiled language for Windows position-independent x86-64 shellcode and Beacon Object Files.☆192Jun 28, 2026Updated 2 months ago
- Cross-platform incident response toolkit. 28 pre-built use cases in a single zero-install binary: triage, threat hunting, memory forensic…☆154Jul 28, 2026Updated last month
- Smuggling C2 comms through links previews☆18Jun 17, 2026Updated 2 months ago
- Windows memory scanner for call stack spoofing detection, unbacked shellcode, injected DLLs and in-memory C2 implants.☆39May 22, 2026Updated 3 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆27May 21, 2026Updated 3 months ago
- KslDump — Why bring your own knife when Defender already left one in the kitchen?☆412Apr 13, 2026Updated 4 months ago
- Phantom is project created to perform loading and executing unmanaged code in memory within an IIS environment running in full‑trust mode…☆107Jun 5, 2026Updated 3 months ago
- Comprehensive Windows Syscall Extraction & Analysis Framework☆173Aug 30, 2025Updated last year
- Microsoft Vulnerable Driver Block Lists in CSV and JSON for SIEM lookups☆55May 15, 2026Updated 3 months ago
- OpenGraph Collector for Tailscale☆44Jul 9, 2026Updated 2 months ago
- A small set of Beacon Object Files (BOFs) that I developed over the time with a Magic: The Gathering theme.☆21Jul 15, 2025Updated last year
- A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike☆242Apr 11, 2026Updated 5 months ago
- Echos is a stealthy C2 traffic emulator built in Rust for Red Teamers. It simulates adversarial beaconing patterns and custom jitter to t…☆34Jul 28, 2026Updated last month
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- 🕵️ Real-time desktop surveillance over HTTP - DXGI capture, MJPEG stream, single C binary, zero dependencies. Built for red teams with n…☆24Jul 28, 2026Updated last month
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 4 months ago
- Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods…☆199Apr 27, 2026Updated 4 months ago
- Test bench lab for Shellcode Obfuscation☆37Sep 2, 2025Updated last year
- A collection of PoCs to do common things in unconventional ways☆122Aug 31, 2025Updated last year
- ☆24Sep 9, 2025Updated last year
- A Beacon Object File (BOF) for Havoc/CS to Bypass PPL and Dump Lsass☆178Sep 22, 2025Updated 11 months ago