Detect userland hooks placed by AV/EDR
☆28Sep 4, 2023Updated 2 years ago
Alternatives and similar repositories for DetectHooks
Users that are interested in DetectHooks are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A simple to use single-include Windows API resolver☆22Jul 9, 2024Updated 2 years ago
- NimReflectiveLoader is a Nim-based tool for in-memory DLL execution using Reflective DLL Loading.☆31Jan 21, 2024Updated 2 years ago
- Cobalt Strike BOFS☆17Dec 20, 2023Updated 2 years ago
- Basic interactive Windows kernel offensive toolkit written in C☆137Sep 20, 2025Updated 10 months ago
- Stealthy Loader-cum-dropper/stage-1/stager targeting Windows10☆37Nov 5, 2022Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Evasive Golang Loader☆136Jul 27, 2024Updated 2 years ago
- ☆24Apr 28, 2024Updated 2 years ago
- Simple EDR that injects a DLL into a process to place a hook on specific Windows API☆99Aug 27, 2023Updated 2 years ago
- "D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system c…☆29Sep 18, 2024Updated last year
- Erebus is a payload generator written in Nim.☆18Jun 13, 2023Updated 3 years ago
- Exploits written while preparing for the OSED exam☆27Apr 30, 2024Updated 2 years ago
- ☆107Sep 5, 2023Updated 2 years ago
- A tool to assist DLL hijacking via the Havoc GUI☆14Jan 9, 2024Updated 2 years ago
- ☆26Mar 10, 2022Updated 4 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Various one-off pentesting projects written in Nim. Updates happen on a whim.☆159May 25, 2026Updated 2 months ago
- Reproducing the SkeletonKey malware.☆11Apr 6, 2024Updated 2 years ago
- PoC for CVE-2023-36802 Microsoft Kernel Streaming Service Proxy☆36Oct 24, 2023Updated 2 years ago
- SOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Dire…☆32May 30, 2024Updated 2 years ago
- A Windows token-theft utility that enumerates SYSTEM processes, duplicates their access token, and spawns a new process running as NT AUT…☆65Mar 26, 2026Updated 4 months ago
- Simple Shellcode Runner in Rust Language☆19Dec 8, 2023Updated 2 years ago
- DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.☆103Sep 18, 2023Updated 2 years ago
- Automatically deploy Nemesis☆21Jun 14, 2024Updated 2 years ago
- GetSystem-LCI is a PowerShell script to escalate privileges from Administrator to NT AUTHORITY\SYSTEM by abusing LanguageComponentsInstal…☆36Nov 24, 2024Updated last year
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- PE obfuscator with Evasion in mind☆212Apr 25, 2023Updated 3 years ago
- shell code example☆69Dec 12, 2025Updated 7 months ago
- DFSCoerce exe revisited version with custom authentication☆43Jan 13, 2024Updated 2 years ago
- Tools/scripts I used/developed during the EXP-301 course.☆27May 17, 2022Updated 4 years ago
- Direct syscalls Injection to bypass AV/EDR☆10May 18, 2024Updated 2 years ago
- This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR …☆258Jul 7, 2022Updated 4 years ago
- A tool for leveraging elevated acess over a computer to boot the computer into Windows Safe Mode, alter settings, and then boot back into…☆17Nov 6, 2021Updated 4 years ago
- A method to execute shellcode using RegisterWaitForInputIdle API.☆54Apr 4, 2023Updated 3 years ago
- ☆19May 22, 2024Updated 2 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆85Aug 13, 2024Updated last year
- Patchless AMSI + ETW bypass via PAGE_GUARD exceptions and Vectored Exception Handler (VEH)☆16Mar 24, 2026Updated 4 months ago
- narly.js - print binary protections with Windbg JS (/SafeSEH, /GS, ASLR, etc.)☆16Nov 14, 2022Updated 3 years ago
- ErebusGate for Nim Bypass AV/EDR☆160Nov 7, 2022Updated 3 years ago
- Process hollowing injection technique for Red Team operations☆18Sep 18, 2023Updated 2 years ago
- Detour hooking IRQ1 ISR through IDT (Interrupt Descriptor Table)☆21Mar 16, 2026Updated 4 months ago
- template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.☆107Jan 10, 2026Updated 7 months ago