EvilBytecode / NoMoreStealersLinks
NoMoreStealers is a Windows file system minifilter driver that protects sensitive user data from untrusted processes.
☆93Updated 2 months ago
Alternatives and similar repositories for NoMoreStealers
Users that are interested in NoMoreStealers are comparing it to the libraries listed below
Sorting:
- Comprehensive Windows Syscall Extraction & Analysis Framework☆160Updated 5 months ago
- .NET tool used to enrich RPC telemetry☆101Updated last week
- A 64 bit executable junk code engine for polymorphic malware.☆75Updated 7 months ago
- EDRStartupHinder: A red team tool to prevent Antivirus and EDR from running.☆180Updated 3 weeks ago
- Bypasses AMSI protection through remote memory patching and parsing technique.☆54Updated 8 months ago
- ☆108Updated last year
- A powerful Windows command-line tool for analyzing and searching ETW (Event Tracing for Windows) provider permissions from the Windows re…☆62Updated 6 months ago
- Obfuscating function calls using Vectored Exception Handlers by redirecting execution through exception-based control flow. Uses byte swa…☆112Updated 3 months ago
- "Service-less" driver loading☆166Updated last year
- Obex – Blocking unwanted DLLs in user mode☆280Updated 4 months ago
- A tool to interact with Windows drivers to perform a raw disk read and parse out target files without calling standard Windows file APIs☆105Updated 5 months ago
- Evade behavioral analysis by executing malicious code within trusted Microsoft call stacks, patchless hooking library IAT/EAT.☆129Updated last month
- A stealthy, assembly-based tool for secure function address resolution, offering a robust alternative to GetProcAddress.☆72Updated last year
- Gain insights into COM/DCOM implementations that may be vulnerable using an automated approach and make it easy to visualize the data. By…☆154Updated 2 months ago
- Malleable shellcode loader written in C and Assembly utilizing direct or indirect syscalls for evading EDR hooks☆136Updated last year
- Commandline spoofing on Windows☆92Updated 2 months ago
- Detection of indirect syscall techniques using hardware breakpoints and vectored exception handling.☆51Updated 3 months ago
- PIC shellcode (C/C++) development toolkit designed for malware developers.☆119Updated last month
- A Windows Named Pipe Multi-tool / Proxy☆283Updated last month
- A slightly more fun way to disable windows defender☆52Updated 9 months ago
- ☆49Updated 2 months ago
- Remote DLL Injection with Timer-based Shellcode Execution☆152Updated 6 months ago
- T-1 is a shellcode loader that leverages ML techniques to detect VM environments☆34Updated last year
- A Payload Analysis Framework☆114Updated 3 months ago
- A unique introduction to native runtime obfuscation.☆74Updated 11 months ago
- 「⚠️」Performing a BYOVD on the truesight.sys driver☆44Updated last year
- A collection of PoCs to do common things in unconventional ways☆122Updated 5 months ago
- A fucking real shellcode loader with a GUI. Work-in-Progress.☆81Updated 7 months ago
- Troll TaskManager, and play with it .☆30Updated 6 months ago
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆83Updated last year