7BitsTeam / EDR-Bypass-demo
Some demos to bypass EDRs or AVs by 78itsT3@m
☆351Updated 2 years ago
Alternatives and similar repositories for EDR-Bypass-demo:
Users that are interested in EDR-Bypass-demo are comparing it to the libraries listed below
- 使用多种WinAPI进行权限维持的CobaltStrike脚本,包含API设置系统服务,设置计划任务,管理用户等。☆540Updated 3 years ago
- dump lsass进程工具☆549Updated last year
- Syscall免杀☆508Updated 10 months ago
- 重构了Cobaltstrike Beacon,行为对国内主流杀软免杀,支持4.1以上的版本。 A cobaltstrike Beacon bypass anti-virus, supports 4.1+ version.☆300Updated 2 years ago
- This is my FirstRepository☆321Updated last year
- 远程shellcode加载&权限维持+小功能☆295Updated 11 months ago
- 创建隐藏计划任务,权限维持,Bypass AV☆532Updated 3 years ago
- CVE-2022-39197 漏洞补丁. CVE-2022-39197 Vulnerability Patch.☆315Updated 2 years ago
- 基于 OPSEC 的 CobaltStrike 后渗透自动化链☆430Updated last year
- EDR绕过demo☆291Updated last year
- 基于Golang实现的Shellcode内存加载器,共实现3中内存加载shellcode方式,UUID加载,MAC加载和IPv4加载,目前能过主流杀软(包括Windows Defender)☆252Updated 3 years ago
- 将dll exe 等转成shellcode 最后输出exe 可定制加载器模板 支持白文件的捆绑 shellcode 加密☆362Updated 2 years ago
- EXE转ShellCode工具☆201Updated 2 years ago
- 风暴免杀-bypass defender、360、vt☆194Updated last year
- Modifying JuicyPotato to support load shellcode and webshell☆190Updated 3 years ago
- 自己开的cs插件☆243Updated 2 years ago
- 一个手动或自动patch shellcode到二进制文件的免杀工具/A tool for manual or automatic patch shellcode into binary file oder to bypass AV.☆474Updated 7 months ago
- 免杀shellcode加载器☆455Updated 3 years ago
- cs4.4修改去特征狗狗版(美化ui,去除特征,自带bypass核晶截图等..)☆571Updated 2 years ago
- 域内自动化信息搜集利用工具☆421Updated last year
- 通过反射DLL注入、Win API、C#、以及底层实现NetUserAdd方式实现BypassAV进行增加用户的功能,实现Cobalt Strike插件化☆333Updated 3 years ago
- Burp插件,Malleable C2 Profiles生成器;可以通过Burp代理选中请求,生成Cobalt Strike的profile文件(CSprofile)☆276Updated 3 years ago
- Red Team C2 Framework with AV/EDR bypass capabilities.☆390Updated last week
- 寻找可利用的白文件☆498Updated 11 months ago
- 适用于Cobalt Strike的插件☆549Updated 3 years ago
- 域信息收集工具☆393Updated 2 years ago
- 针对PE文件的分离的攻防对抗工具,红队、研究者的好帮手。目前支持文件头伪装、证书区段感染。A no-kill confrontation tool for the separation of PE files, a good helper for red teams and…☆256Updated 8 months ago
- Bypass_AV msf免杀,ShellCode免杀加载器 ,免杀shellcode执行程序 ,360&火绒&Windows Defender☆224Updated 2 years ago
- 添加计划任务方法集合☆279Updated last year
- 免杀,bypassav,免杀框架,nim,shellcode,使用nim编写的shellcode加载器☆656Updated 2 months ago