Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET assemblies. it works with a multi-layer confidence model that dramatically reduce the false positive rate and hunt for malicious behaviour.
☆58Jul 5, 2026Updated last month
Alternatives and similar repositories for aether
Users that are interested in aether are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.☆86Jun 15, 2026Updated 2 months ago
- Modern Web Application Firewall for Kong Gateway☆28Updated this week
- DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them agai…☆36Jul 28, 2026Updated 3 weeks ago
- ☆24May 19, 2026Updated 3 months ago
- Indicators of Normality☆11Jul 22, 2022Updated 4 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Proof-of-concept security demo illustrating how PowerShell can create trusted-looking Windows toast notifications chained together with C…☆18Apr 12, 2026Updated 4 months ago
- Helps defenders find their WSUS configurations in the wake of CVE-2025-59287☆46Oct 28, 2025Updated 9 months ago
- Async BOF that notifies the operator when a user connects to a local or remote target system.☆34Jul 30, 2026Updated 3 weeks ago
- Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID☆181Jul 10, 2026Updated last month
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.☆55Mar 30, 2026Updated 4 months ago
- Evasive loader for .NET Framework assemblies☆83May 12, 2026Updated 3 months ago
- User-mode ETW interception and telemetry manipulation lab for Windows security research.☆44Jun 15, 2026Updated 2 months ago
- Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijac…☆157Jul 20, 2026Updated last month
- This repository contains the research tool presented at x33fcon 2026, along with the associated presentation slides. The content is made …☆64Jun 15, 2026Updated 2 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Repo hacks☆21Jul 30, 2026Updated 3 weeks ago
- Repository hosting a hypothetical EDR Spoofer, as discovered originally by Nightmare-Eclipse☆43May 27, 2026Updated 2 months ago
- Janus analyzes C2 telemetry to surface failure patterns, operator friction, and automation opportunities across engagements.☆58Jun 23, 2026Updated 2 months ago
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆27May 10, 2026Updated 3 months ago
- A compiled language for Windows position-independent x86-64 shellcode and Beacon Object Files.☆180Jun 28, 2026Updated last month
- Sanctum is an experimental proof-of-concept EDR, designed to detect modern malware techniques, above and beyond the capabilities of antiv…☆568Mar 24, 2026Updated 4 months ago
- Cross-platform incident response toolkit. 28 pre-built use cases in a single zero-install binary: triage, threat hunting, memory forensic…☆154Jul 28, 2026Updated 3 weeks ago
- Smuggling C2 comms through links previews☆18Jun 17, 2026Updated 2 months ago
- Windows memory scanner for call stack spoofing detection, unbacked shellcode, injected DLLs and in-memory C2 implants.☆39May 22, 2026Updated 3 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- KslDump — Why bring your own knife when Defender already left one in the kitchen?☆399Apr 13, 2026Updated 4 months ago
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆27May 21, 2026Updated 3 months ago
- Phantom is project created to perform loading and executing unmanaged code in memory within an IIS environment running in full‑trust mode…☆108Jun 5, 2026Updated 2 months ago
- Comprehensive Windows Syscall Extraction & Analysis Framework☆172Aug 30, 2025Updated 11 months ago
- Microsoft Vulnerable Driver Block Lists in CSV and JSON for SIEM lookups☆55May 15, 2026Updated 3 months ago
- OpenGraph Collector for Tailscale☆43Jul 9, 2026Updated last month
- A small set of Beacon Object Files (BOFs) that I developed over the time with a Magic: The Gathering theme.☆21Jul 15, 2025Updated last year
- A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike☆240Apr 11, 2026Updated 4 months ago
- Echos is a stealthy C2 traffic emulator built in Rust for Red Teamers. It simulates adversarial beaconing patterns and custom jitter to t…☆34Jul 28, 2026Updated 3 weeks ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- 🕵️ Real-time desktop surveillance over HTTP - DXGI capture, MJPEG stream, single C binary, zero dependencies. Built for red teams with n…☆24Jul 28, 2026Updated 3 weeks ago
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 3 months ago
- Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods…☆197Apr 27, 2026Updated 3 months ago
- Test bench lab for Shellcode Obfuscation☆36Sep 2, 2025Updated 11 months ago
- A collection of PoCs to do common things in unconventional ways☆121Aug 31, 2025Updated 11 months ago
- ☆18Sep 9, 2025Updated 11 months ago
- A Beacon Object File (BOF) for Havoc/CS to Bypass PPL and Dump Lsass☆178Sep 22, 2025Updated 11 months ago