ANYLNK / NSecSoftBYOVDView external linksLinks
NSecSoftBYOVD POC
☆55Updated this week
Alternatives and similar repositories for NSecSoftBYOVD
Users that are interested in NSecSoftBYOVD are comparing it to the libraries listed below
Sorting:
- ☆41Updated this week
- Beacon Object Files (BOFs) for Cobalt Strike and Havoc C2. Implementations of Active Directory attacks and post-exploitation techniques.☆98Jan 26, 2026Updated 3 weeks ago
- process hollowing variant using NtCreateSection + NtMapViewOfSection + ResumeThread☆31Jan 9, 2022Updated 4 years ago
- BYOVD Technique Example using viragt64 driver☆69Jul 25, 2024Updated last year
- Templates for developing your own listeners and agents for AdaptixC2.☆44Feb 3, 2026Updated last week
- A Rust template for writing Beacon Object Files (BOFs)☆87Updated this week
- Unix Process hollowing in rust☆22Dec 16, 2024Updated last year
- Rusty Mimikatz - All credits to: github.com/ThottySploity/mimiRust (Original author deleted account so I uploaded for community use)☆20Nov 24, 2022Updated 3 years ago
- EDR-Redir : a tool used to redirect the EDR's folder to another location.☆222Nov 6, 2025Updated 3 months ago
- C++ tool and library for converting .bin files to shellcode in multiple output formats.☆33Aug 18, 2025Updated 5 months ago
- Rust malware EDR evasion via direct syscalls, fully implemented as an example in Rust☆82Jun 4, 2024Updated last year
- CVE-2024-35250 的 Beacon Object File (BOF) 实现。☆24Nov 28, 2024Updated last year
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆88Jan 2, 2026Updated last month
- Waiting Thread Hijacking - injection by overwriting the return address of a waiting thread☆262Aug 31, 2025Updated 5 months ago
- ☆55May 31, 2025Updated 8 months ago
- ShadowDropper is a utility for covertly delivering and executing payloads on a target system.☆26Jul 4, 2025Updated 7 months ago
- This is a VxLAN PoC code for Talks: From Spoofing to Tunneling: New Red Team's Networking Techniques for Initial Access and Evasion☆28Jul 21, 2025Updated 6 months ago
- Some security by obscurity using port-jumping.☆14Aug 21, 2025Updated 5 months ago
- collection of beacon object file (Cobalt strike)☆12Jan 21, 2023Updated 3 years ago
- Enable EFS service as low priv user (PE & BOF)☆21Jul 6, 2025Updated 7 months ago
- PoC exploit for the vulnerable WatchDog Anti-Malware driver (amsdk.sys) – weaponized to kill protected EDR/AV processes via BYOVD.☆180Sep 11, 2025Updated 5 months ago
- ☆52Sep 26, 2024Updated last year
- .NET assembly loader with patching AMSI and ETW bypass☆31Apr 16, 2025Updated 10 months ago
- Windows C++ Implant for Exploration C2☆44Jan 26, 2026Updated 3 weeks ago
- Abusing SSRF to deliver an authenticated command injection payload☆30Sep 1, 2025Updated 5 months ago
- Group Policy Objects manipulation and exploitation framework☆289Dec 7, 2025Updated 2 months ago
- A simple script to elevate current session to SYSTEM (needs to be run as Administrator)☆15Nov 11, 2024Updated last year
- Repository of different kernel drivers written while studying Windows NT Driver development☆12Apr 14, 2024Updated last year
- GetModuleHandle (via PEB) and GetProcAddress (via EAT) like☆32Feb 7, 2022Updated 4 years ago
- Enumerate active EDR's on the system☆150Sep 23, 2025Updated 4 months ago
- Dump processes over WMI with MSFT_MTProcess☆81Updated this week
- This is the loader that supports running a program with Protected Process Light (PPL) protection functionality.☆294Nov 1, 2025Updated 3 months ago
- ☆58Jul 31, 2025Updated 6 months ago
- A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.☆15Apr 4, 2023Updated 2 years ago
- ☆14Dec 26, 2024Updated last year
- A tool to assist DLL hijacking via the Havoc GUI☆12Jan 9, 2024Updated 2 years ago
- A small set of Beacon Object Files (BOFs) that I developed over the time with a Magic: The Gathering theme.☆16Jul 15, 2025Updated 7 months ago
- Cobalt Strike Beacon Object File (BOF) that obtain SYSTEM privilege with SeImpersonate privilege by passing a malicious IUnknwon object t…☆13Feb 4, 2024Updated 2 years ago
- Call Stack Spoofing for Rust☆210Jan 28, 2026Updated 2 weeks ago