CymulateResearch / Blindside
Utilizing hardware breakpoints to evade monitoring by Endpoint Detection and Response platforms
☆109Updated last year
Related projects ⓘ
Alternatives and complementary repositories for Blindside
- I have documented all of the AMSI patches that I learned till now☆68Updated last year
- Beacon Object File allowing creation of Beacons in different sessions.☆76Updated 2 years ago
- Tool for playing with Windows Access Token manipulation.☆51Updated last year
- A Poc on blocking Procmon from monitoring network events☆97Updated 2 years ago
- A basic meterpreter protocol stager using the libpeconv library by hasherezade for reflective loading☆83Updated last year
- RDLL for Cobalt Strike beacon to silence sysmon process☆85Updated 2 years ago
- Section Mapping Process Injection (secinject): Cobalt Strike BOF☆87Updated 2 years ago
- Patch AMSI and ETW in remote process via direct syscall☆77Updated 2 years ago
- ☆105Updated last year
- Sleep Obfuscation☆41Updated 2 years ago
- ☆61Updated 2 years ago
- Simple BOF to read the protection level of a process☆104Updated last year
- This is my own implementation of the Perun's Fart technique by Sektor7☆66Updated 2 years ago
- ☆95Updated last year
- this repo is to cover the other undocumented or published / in different langaue to achieve shellcode injection via windows callback func…☆82Updated 2 years ago
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆94Updated last year
- Implant drop-in for EDR testing☆127Updated 11 months ago
- Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged☆86Updated 2 years ago
- DynamicSyscalls is a library written in .net resolves the syscalls dynamically (Has nothing to do with hooking/unhooking)☆63Updated last year
- Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel space☆120Updated last year
- ☆139Updated last year
- ☆121Updated 11 months ago
- Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post☆86Updated 2 years ago
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆78Updated last year
- A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge …☆159Updated last year