Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET assemblies. it works with a multi-layer confidence model that dramatically reduce the false positive rate and hunt for malicious behaviour.
☆57Jul 5, 2026Updated 3 weeks ago
Alternatives and similar repositories for aether
Users that are interested in aether are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.☆87Jun 15, 2026Updated last month
- Modern Web Application Firewall for Kong Gateway☆28Updated this week
- DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them agai…☆36Updated this week
- ☆23May 19, 2026Updated 2 months ago
- Indicators of Normality☆11Jul 22, 2022Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Proof-of-concept security demo illustrating how PowerShell can create trusted-looking Windows toast notifications chained together with C…☆18Apr 12, 2026Updated 3 months ago
- Helps defenders find their WSUS configurations in the wake of CVE-2025-59287☆46Oct 28, 2025Updated 9 months ago
- Async BOF that notifies the operator when a user connects to a local or remote target system.☆34Updated this week
- Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID☆179Jul 10, 2026Updated 3 weeks ago
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.☆56Mar 30, 2026Updated 4 months ago
- Evasive loader for .NET Framework assemblies☆83May 12, 2026Updated 2 months ago
- User-mode ETW interception and telemetry manipulation lab for Windows security research.☆43Jun 15, 2026Updated last month
- Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijac…☆136Jul 20, 2026Updated 2 weeks ago
- This repository contains the research tool presented at x33fcon 2026, along with the associated presentation slides. The content is made …☆62Jun 15, 2026Updated last month
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Repo hacks☆21Updated this week
- Repository hosting a hypothetical EDR Spoofer, as discovered originally by Nightmare-Eclipse☆41May 27, 2026Updated 2 months ago
- Janus analyzes C2 telemetry to surface failure patterns, operator friction, and automation opportunities across engagements.☆56Jun 23, 2026Updated last month
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆27May 10, 2026Updated 2 months ago
- A compiled language for Windows position-independent x86-64 shellcode and Beacon Object Files.☆176Jun 28, 2026Updated last month
- Sanctum is an experimental proof-of-concept EDR, designed to detect modern malware techniques, above and beyond the capabilities of antiv…☆567Mar 24, 2026Updated 4 months ago
- Cross-platform incident response toolkit. 28 pre-built use cases in a single zero-install binary: triage, threat hunting, memory forensic…☆154Updated this week
- Smuggling C2 comms through links previews☆18Jun 17, 2026Updated last month
- Windows memory scanner for call stack spoofing detection, unbacked shellcode, injected DLLs and in-memory C2 implants.☆37May 22, 2026Updated 2 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- KslDump — Why bring your own knife when Defender already left one in the kitchen?☆398Apr 13, 2026Updated 3 months ago
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆27May 21, 2026Updated 2 months ago
- Phantom is project created to perform loading and executing unmanaged code in memory within an IIS environment running in full‑trust mode…☆106Jun 5, 2026Updated last month
- Comprehensive Windows Syscall Extraction & Analysis Framework☆172Aug 30, 2025Updated 11 months ago
- Microsoft Vulnerable Driver Block Lists in CSV and JSON for SIEM lookups☆55May 15, 2026Updated 2 months ago
- OpenGraph Collector for Tailscale☆43Jul 9, 2026Updated 3 weeks ago
- A small set of Beacon Object Files (BOFs) that I developed over the time with a Magic: The Gathering theme.☆21Jul 15, 2025Updated last year
- Echos is a stealthy C2 traffic emulator built in Rust for Red Teamers. It simulates adversarial beaconing patterns and custom jitter to t…☆34Jul 28, 2026Updated last week
- A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike☆238Apr 11, 2026Updated 3 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- 🕵️ Real-time desktop surveillance over HTTP - DXGI capture, MJPEG stream, single C binary, zero dependencies. Built for red teams with n…☆21Updated this week
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 2 months ago
- Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods…☆197Apr 27, 2026Updated 3 months ago
- Test bench lab for Shellcode Obfuscation☆37Sep 2, 2025Updated 11 months ago
- A collection of PoCs to do common things in unconventional ways☆121Aug 31, 2025Updated 11 months ago
- ☆18Sep 9, 2025Updated 10 months ago
- A Beacon Object File (BOF) for Havoc/CS to Bypass PPL and Dump Lsass☆180Sep 22, 2025Updated 10 months ago