HackerCalico / SigLocator
Efficient RAT signature locator for bypassing AV/EDR, supporting static scanning and memory scanning.
☆15Updated 2 weeks ago
Related projects ⓘ
Alternatives and complementary repositories for SigLocator
- Red team tool designed for quickly identifying hijackable programs, evading antivirus software, and EDR (Endpoint Detection and Response)…☆58Updated 6 months ago
- Binary Hollowing☆53Updated 2 months ago
- vehsyscall:a syscall project that may bypass EDR☆42Updated 8 months ago
- Shellcode Reductio Entropy Tools☆63Updated last year
- Self Cleanup in post-ex job☆42Updated 2 months ago
- ☆49Updated last year
- CobaltStrike4.5 Sleeve解密文件,搬砖加一点点修改, 仅作备份使用.☆30Updated 2 years ago
- more conveniently Visual-Studio-BOF-template☆53Updated last year
- ☆22Updated last year
- Amazing Obfuscator; 支持混淆 ShellCode 甚至 EXE; Support obfuscating ShellCode, even EXE.☆31Updated this week
- Resolve the issue of DLLmain function in white and black DLLs hanging when calling shellcode☆104Updated 5 months ago
- beta☆111Updated last month
- Cobalt Strike BOF that Add a user to localgroup by samr☆123Updated last year
- BOF implementation of delete self poc that delete a locked executable or a currently running file from disk by its pid, path, or the curr…☆67Updated last year
- 一个2020年练手的基于gin框架搞的在线免杀平台,支持后台管理,邀请码注册等☆34Updated 2 months ago
- 免杀计划任务进行权限维持,过主流杀软。 A schtask tool bypass anti-virus☆66Updated 2 years ago
- Beta Linker☆19Updated 2 months ago
- Delete file regardless of whether the handle is used via SetFileInformationByHandle☆40Updated last year
- ☆28Updated last year
- kill AV/EDR☆21Updated last year
- xiebroC2 plugin☆36Updated 2 months ago
- command execute without 445 port☆51Updated 2 years ago
- Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from mem…☆32Updated 6 months ago
- Rust 重构的 sRDI☆11Updated 2 months ago
- 利用EFSRPC协议批量探测出网☆65Updated last year
- Bypass EDR Create TaskServers☆34Updated last year
- C# based tool which automates the process of discovering and exploiting DLL Hijacks in target binaries. The Hijacked paths discovered can…☆17Updated 3 years ago
- Hidedump:a lsassdump tools that may bypass EDR☆35Updated 5 months ago
- 用于解密并加载shellcode,支持RC4和AES两种解密方法,并使用DInvoke来动态调用WinAPI函数,从而尝试绕过某些安全解决方案☆29Updated last year