BlackShell256 / Amsi-BypassLinks
Bypass Amsi powershell of Matt Graeber modified
☆8Updated last year
Alternatives and similar repositories for Amsi-Bypass
Users that are interested in Amsi-Bypass are comparing it to the libraries listed below
Sorting:
- PoC MSI payload based on ASEC/AhnLab's blog post☆23Updated 2 years ago
- Find kernel32 base and API addresses. Simple C++ implementation☆24Updated 3 years ago
- ☆10Updated 3 years ago
- Beacon Object Files used for Cobalt Strike☆19Updated last year
- Extension functionality for the NightHawk operator client☆27Updated last year
- ☆18Updated 6 months ago
- freeBokuLoader fork which targets and frees Metsrv's initial reflective DLL package☆33Updated 2 years ago
- Yet, Another Packer/Loader☆25Updated 2 years ago
- A more advanced free and open .NET obfuscator using dnlib.☆10Updated 2 years ago
- A PoC~ish of https://elastic.github.io/security-research/malware/2022/01/01.operation-bleeding-bear/article/☆31Updated last year
- A simple rpc2socks alternative in pure Go.☆28Updated 10 months ago
- Giga-byte Control Center (GCC) is a software package designed for improved user experience of Gigabyte hardware, often found in gaming an…☆31Updated 2 years ago
- Quickly generate every payload type for each listener and optionally host via HTTP.☆22Updated 3 years ago
- powershell script i wrote that can suspend an arbitrary process (with limits)☆20Updated 2 years ago
- JALSI - Just Another Lame Shellcode Injector☆30Updated 3 years ago
- An adaptation of timwhitez's proxycall that uses kernelbase.dll!Beep.☆12Updated last year
- Executes shellcode from a remote server and aims to evade in-memory scanners☆31Updated 5 years ago
- A collection of random small Aggressor snippets that don't warrant their own repo☆23Updated 2 years ago
- ☆15Updated last year
- DoublePulsar (Position-Independent) Shellcode (Windows 7 SP1 x64)☆27Updated 5 years ago
- ☆12Updated 2 years ago
- A simple Nim stager (w/ fiber execution)☆18Updated 3 years ago
- Another AMSI bypass - but in C++.☆23Updated 2 years ago
- A PoC executing shellcode in Dart☆15Updated 2 years ago
- ☆18Updated last year
- ManageEngine ADManager Command Injection☆11Updated last year
- C code to enable ETW tracing for Dotnet Assemblies☆31Updated 2 years ago
- This repository contains several AMSI bypasses. These bypasses are based on some very nice research that has been put out by some awesome…☆24Updated 2 years ago
- A repository filled with ideas to break/detect direct syscall techniques☆27Updated 3 years ago
- This POC provides the possibilty to execute x86 shellcode in form of a .bin file based on x86 inline assembly☆18Updated 2 years ago