Evasions encyclopedia gathers methods used by malware to evade detection when run in virtualized environment. Methods are grouped into categories for ease of searching and understanding. Also provided are code samples, signature recommendations and countermeasures within each category for the described techniques.
☆446Mar 31, 2026Updated 6 months ago
Alternatives and similar repositories for Evasions
Users that are interested in Evasions are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- InviZzzible is a tool for assessment of your virtual environments in an easy and reliable way. It contains the most recent and up to date…☆587Mar 31, 2026Updated 6 months ago
- A more stealthy variant of "DLL hollowing"☆369Mar 8, 2024Updated 2 years ago
- A PoC~ish of https://elastic.github.io/security-research/malware/2022/01/01.operation-bleeding-bear/article/☆30Feb 26, 2024Updated 2 years ago
- Anti-virus artifacts. Listing APIs hooked by: Avira, BitDefender, F-Secure, MalwareBytes, Norton, TrendMicro, and WebRoot.☆760Nov 16, 2021Updated 4 years ago
- Small and convenient C2 tool for Windows targets☆622Mar 8, 2022Updated 4 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- MSBuild without MSbuild.exe☆135Dec 21, 2020Updated 5 years ago
- Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.☆7,141Jul 1, 2026Updated 3 months ago
- Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll☆517Feb 3, 2022Updated 4 years ago
- Collection of beacon BOF written to learn windows and cobaltstrike☆360Feb 24, 2023Updated 3 years ago
- A shellcode function to encrypt a running process image when sleeping.☆337Sep 11, 2021Updated 5 years ago
- SysWhispers on Steroids - AV/EDR evasion via direct system calls.☆1,666Jul 31, 2024Updated 2 years ago
- Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the in…☆1,209Jul 5, 2023Updated 3 years ago
- ☆108May 14, 2018Updated 8 years ago
- UnhookMe is an universal Windows API resolver & unhooker addressing problem of invoking unmonitored system calls from within of your Red …☆347Jul 3, 2022Updated 4 years ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Open-Source Shellcode & PE Packer☆2,138Feb 3, 2024Updated 2 years ago
- Shellcode runner in GO that incorporates shellcode encryption, remote process injection, block dlls, and spoofed parent process☆227Jul 30, 2020Updated 6 years ago
- Evasive shellcode loader for bypassing event-based injection detection (PoC)☆835Aug 23, 2021Updated 5 years ago
- Sandbox evasion modules written in PowerShell, Python, Go, Ruby, C, C#, Perl, and Rust.☆930Jun 1, 2021Updated 5 years ago
- LiquidSnake is a tool that allows operators to perform fileless lateral movement using WMI Event Subscriptions and GadgetToJScript☆351Sep 1, 2021Updated 5 years ago
- AV/EDR evasion via direct system calls.☆2,026Jan 1, 2023Updated 3 years ago
- C/C++ source obfuscator for antivirus bypass☆1,069Mar 10, 2022Updated 4 years ago
- Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing…☆1,790Jan 16, 2026Updated 8 months ago
- Adaptive DLL hijacking / dynamic export forwarding☆818Jul 6, 2020Updated 6 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Tool to create hidden registry keys.☆489Oct 23, 2019Updated 6 years ago
- ☆830Dec 28, 2019Updated 6 years ago
- Using DInvoke to patch AMSI.dll in order to bypass AMSI detections triggered when loading .NET tradecraft via Assembly.Load().☆216Mar 5, 2020Updated 6 years ago
- A technique of hiding malicious shellcode via Shannon encoding.☆269Oct 23, 2022Updated 3 years ago
- Enumerate and disable common sources of telemetry used by AV/EDR.☆864Mar 11, 2021Updated 5 years ago
- AMSI Bypass Via the Heap☆106Nov 20, 2020Updated 5 years ago
- Also known by Microsoft as Knifecoat☆1,144Dec 22, 2022Updated 3 years ago
- Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique☆337Jan 16, 2022Updated 4 years ago
- Evade sysmon and windows event logging☆624Apr 8, 2020Updated 6 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- AV/EDR evasion via direct system calls.☆1,828Sep 3, 2022Updated 4 years ago
- LSASS memory dumper using direct system calls and API unhooking.☆1,596Jan 5, 2021Updated 5 years ago
- Tool for interacting with outlook interop during red team engagements☆145Jun 29, 2021Updated 5 years ago
- ☆429Apr 28, 2021Updated 5 years ago
- A protective and Low Level Shellcode Loader that defeats modern EDR systems.☆913Mar 20, 2024Updated 2 years ago
- A simple COM server which provides a component to run shellcode☆142May 12, 2020Updated 6 years ago
- Red Team C code repo☆573Dec 16, 2024Updated last year