Helixo32 / SimpleEDR
Simple EDR that injects a DLL into a process to place a hook on specific Windows API
☆89Updated last year
Alternatives and similar repositories for SimpleEDR:
Users that are interested in SimpleEDR are comparing it to the libraries listed below
- Two in one, patch lifetime powershell console, no more etw and amsi!☆83Updated 7 months ago
- Utilities for obfuscating shellcode☆51Updated 7 months ago
- Slide decks and/or materials from conference presentations☆55Updated 2 years ago
- Living Off the Foreign Land setup scripts☆64Updated last month
- Sleep obfuscation for shellcode implants and their reflective shit☆51Updated last year
- Grab NetNTLMv2 hashes using ETW with administrative rights on Windows 8.1 / Windows Server 2016 and later☆91Updated last year
- Python module for running BOFs☆68Updated last year
- ☆71Updated last year
- IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then refle…☆109Updated 9 months ago
- Small project to facilitate creation of .lnk payloads☆63Updated 2 years ago
- Lifetime AMSI bypass.☆35Updated 7 months ago
- Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctype…☆110Updated last year
- Just another C2 Redirector using CloudFlare.☆86Updated 9 months ago
- Abuse Azure API permissions for red teaming☆61Updated 2 years ago
- Living off the land searches for explorer and sharepoint☆56Updated 3 months ago
- AAD related enumeration in Nim☆128Updated last year
- Example code samples from our ScriptBlock Smuggling Blog post☆88Updated 8 months ago
- ☆85Updated 2 years ago
- Various one-off pentesting projects written in Nim. Updates happen on a whim.☆149Updated last month
- Your syscall factory☆120Updated last month
- Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post☆90Updated 2 years ago
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆51Updated 9 months ago
- Lateral Movement☆122Updated last year
- ☆139Updated 6 months ago
- AzureAD beacon object files☆109Updated 2 months ago
- C# implementation of TokenFinder. Steal M365 access tokens from Office Desktop apps☆135Updated 6 months ago
- Embedder is a collection of sources in different languages to embed Python interpreter with minimal dependencies☆115Updated 8 months ago
- Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged☆86Updated 2 years ago
- Simple BOF to read the protection level of a process☆114Updated last year
- Impacket pre-compiled binaries☆15Updated last year