Rex Shellcode Loader for AV/EDR evasion
☆36Apr 7, 2024Updated 2 years ago
Alternatives and similar repositories for RexLdr
Users that are interested in RexLdr are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Evasive shellcode loader with indirect syscalls, Thread name-calling allocation, PoolParty injection☆10Feb 26, 2025Updated last year
- BloodyAv is Custom Shell Code loader to Bypass Av and Edr.☆15Mar 21, 2022Updated 4 years ago
- 一个普通的BOF用来BypassUAC☆22Apr 6, 2024Updated 2 years ago
- Something with wine. I always wanted to try that out, but never had the time. Now I do.☆23Jul 26, 2023Updated 3 years ago
- ☆63Apr 4, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Bypass EDR(Endpoint Detection and Response) environment to write Behinder jsp webshell onto webserver☆13Dec 27, 2023Updated 2 years ago
- ☆16Jan 2, 2025Updated last year
- inspired by mr d0x filefix☆16Feb 4, 2026Updated 6 months ago
- EDR/AV Simulation for Malware Development☆13Oct 21, 2023Updated 2 years ago
- A memory-based evasion technique which makes shellcode invisible from process start to end.☆17Aug 14, 2023Updated 3 years ago
- 密码生成工具、password maker、password generator☆15Apr 20, 2024Updated 2 years ago
- 个人学习使用,二开DcRAT,主要是增加了功能性插件☆17Jan 26, 2024Updated 2 years ago
- Event Tracing for Windows EDR bypass in Rust (usermode)☆40Jun 9, 2024Updated 2 years ago
- Massayo is a small proof-of-concept Rust library which removes AV/EDR hooks in a given system DLL☆64Sep 12, 2022Updated 3 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Another approach of Threadless injection discovered by @_EthicalChaos_ in c that loads a module into the target process and stomps it, an…☆187Aug 2, 2023Updated 3 years ago
- AV/EDR killer using BYOVD technique☆45Sep 27, 2024Updated last year
- Indirect Syscall invocation via thread hijacking☆27May 5, 2023Updated 3 years ago
- Command line & PPID spoofing☆31Apr 15, 2023Updated 3 years ago
- TangGo的自定义界面工具模块设计和分享的第三方工具界面☆11Nov 27, 2024Updated last year
- 内存加载DLL 支持VMP最大加密☆12Aug 11, 2020Updated 6 years ago
- A single byte modification in the kernel memory bypasses and disables all core functions of the AV/EDR security solutions☆17Aug 26, 2025Updated 11 months ago
- Mockingjay process self injection POC☆54Aug 8, 2023Updated 3 years ago
- Replace the .txt section of the current loaded modules from \KnownDlls\☆307Sep 28, 2022Updated 3 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Bypassing AV, EDR, Application Whitelisting and ASR Rules☆13Apr 18, 2023Updated 3 years ago
- Titan: A generic user defined reflective DLL for Cobalt Strike☆85Nov 20, 2022Updated 3 years ago
- HexRaysPyTools merged! (@NyaMisty @oopsmishap @Tim-Sobolev @OrbitOn-line)☆17Dec 15, 2025Updated 8 months ago
- Slides and POC demo for my talk at Divizion Zero on EDR evasion titled "Evasion Adventures"☆31Jan 14, 2023Updated 3 years ago
- A TCP implementation over a tun device☆14Jul 25, 2026Updated 3 weeks ago
- A Beacon Object File for decrypting Chrome App-Bound Encryption masterkeys in-memory via Cobalt Strike☆18Jul 14, 2025Updated last year
- Probably the easiest way to setup new beacon notifications in Cobalt Strike☆10Jan 7, 2022Updated 4 years ago
- A new technique that can be used to bypass memory scanners. This can be useful in hiding problematic code (such as reflective loaders imp…☆360Oct 7, 2024Updated last year
- reflectively load and execute PEs locally and remotely bypassing EDR hooks☆169Jan 4, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- 无Windows API的新型恶意程序:自缺陷程序利用堆栈溢出的隐匿稳定攻击技术研究,A new type of malicious program without Windows API☆90Mar 27, 2025Updated last year
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆50May 8, 2024Updated 2 years ago
- Two C# RunPE's capable of x86 and x64 injections☆11Dec 2, 2018Updated 7 years ago
- narly.js - print binary protections with Windbg JS (/SafeSEH, /GS, ASLR, etc.)☆16Nov 14, 2022Updated 3 years ago
- This code example allows you to create a malware.exe sample that can be run in the context of a system service, and could be used for loc…☆55May 8, 2023Updated 3 years ago
- Remap ntdll.dll using only NTAPI functions with a suspended process☆27Apr 13, 2025Updated last year
- A WIP shellcode loader tool which bypasses AV/EDR, coded in C++, and equipped with a minimal builder.☆87Sep 27, 2025Updated 10 months ago