Helixo32 / SimpleEDR
Simple EDR that injects a DLL into a process to place a hook on specific Windows API
☆90Updated last year
Alternatives and similar repositories for SimpleEDR:
Users that are interested in SimpleEDR are comparing it to the libraries listed below
- Two in one, patch lifetime powershell console, no more etw and amsi!☆86Updated 9 months ago
- Living Off the Foreign Land setup scripts☆67Updated last month
- Slide decks and/or materials from conference presentations☆56Updated 2 years ago
- ☆88Updated 2 years ago
- Indirect syscalls + DInvoke made simple.☆90Updated 3 months ago
- Simple BOF to read the protection level of a process☆114Updated last year
- Your syscall factory☆121Updated last month
- Grab NetNTLMv2 hashes using ETW with administrative rights on Windows 8.1 / Windows Server 2016 and later☆91Updated last year
- Adversary Emulation Framework☆96Updated 8 months ago
- IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then refle…☆111Updated 11 months ago
- Microsoft Graph API post-exploitation toolkit☆94Updated 9 months ago
- A Python POC for CRED1 over SOCKS5☆147Updated 6 months ago
- ☆116Updated last year
- Example code samples from our ScriptBlock Smuggling Blog post☆90Updated 10 months ago
- A collection of various and sundry code snippets that leverage .NET dynamic tradecraft☆142Updated 11 months ago
- Lateral Movement☆122Updated last year
- BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR☆75Updated last year
- Python module for running BOFs☆68Updated last year
- ☆117Updated 3 weeks ago
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆81Updated 2 years ago
- Just another C2 Redirector using CloudFlare. Support multiple C2 and multiple domains. Support for websocket listener.☆153Updated last month
- Lateral Movement via the .NET Profiler☆80Updated 4 months ago
- Leveraging AWS Lambda Function URLs for C2 Redirection☆31Updated last year
- Various one-off pentesting projects written in Nim. Updates happen on a whim.☆151Updated 3 months ago
- C# implementation of TokenFinder. Steal M365 access tokens from Office Desktop apps☆138Updated 8 months ago
- A variation of ProcessOverwriting to execute shellcode on an executable's section☆148Updated last year
- ☆71Updated last year
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆47Updated 11 months ago
- Small project to facilitate creation of .lnk payloads☆65Updated 2 years ago
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆52Updated 11 months ago