AV Evasion Techniques
☆83Jul 28, 2022Updated 4 years ago
Alternatives and similar repositories for evasion
Users that are interested in evasion are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Windows Post-Exploitation tools wrapper☆12Jun 24, 2024Updated 2 years ago
- Linux Post-Exploitation tools wrapper☆20Mar 21, 2023Updated 3 years ago
- Run PowerShell command without invoking powershell.exe☆27Apr 9, 2026Updated 4 months ago
- Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged☆89Jul 7, 2022Updated 4 years ago
- Patch AMSI and ETW☆251May 8, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A repository with my notable code snippets for Offensive Security's PEN-300 (OSEP) course.☆1,463Jul 27, 2025Updated last year
- Proof-of-concept obfuscation toolkit for C# post-exploitation tools☆637Jul 22, 2022Updated 4 years ago
- PEN-300 collection to help you on your exam.☆729Feb 25, 2026Updated 5 months ago
- DLL sideloading techniques for stealthy payload execution on Windows☆94Sep 20, 2023Updated 2 years ago
- A new AMSI Bypass technique using .NET ALI Call Hooking.☆195Nov 15, 2022Updated 3 years ago
- random code snippets, useful for getting started☆124Nov 29, 2025Updated 8 months ago
- ☆19Jan 11, 2023Updated 3 years ago
- ☆1,705Apr 14, 2025Updated last year
- C# havoc implant☆100Feb 12, 2023Updated 3 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Simple & Powerful PowerShell Script Obfuscator☆596May 13, 2025Updated last year
- Loads any C# binary in mem, patching AMSI + ETW.☆853Oct 3, 2021Updated 4 years ago
- ☆20Aug 10, 2022Updated 4 years ago
- Expeditus is a loader that executes shellcode on a target Windows system. It combines several offensive techniques in order to attempt to…☆13May 30, 2022Updated 4 years ago
- Local privilege escalation from SeImpersonatePrivilege using EfsRpc.☆348Oct 17, 2022Updated 3 years ago
- This POC gives you the possibility to compile a .exe to completely avoid statically detection by AV/EPP/EDR of your C2-shellcode and down…☆257May 25, 2023Updated 3 years ago
- Bypass AMSI by patching AmsiScanBuffer☆284Jun 4, 2021Updated 5 years ago
- This repo contains some Amsi Bypass methods i found on different Blog Posts.☆2,189Nov 28, 2024Updated last year
- Fileless lateral movement tool that relies on ChangeServiceConfigA to run command☆1,654Jul 10, 2023Updated 3 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Arbitrary file read exploit for the Windows UPnP Device Host service.☆20Jun 5, 2026Updated 2 months ago
- SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.☆1,220Apr 16, 2025Updated last year
- Efflanrs - GUI for Snaffler Output☆27Sep 13, 2024Updated last year
- A windows token impersonation tool☆329Apr 19, 2023Updated 3 years ago
- Powershell tool to automate Active Directory enumeration.☆1,357Jul 28, 2026Updated 3 weeks ago
- ☆70Aug 2, 2022Updated 4 years ago
- Creating a Malicious Macro using MS Word☆26Jun 10, 2022Updated 4 years ago
- A launcher to load a DLL with xored cobalt strike shellcode executed in memory through process hollowing technique☆29Nov 11, 2022Updated 3 years ago
- CVE's we discovered along the way☆17Oct 18, 2021Updated 4 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- A C# port of the MinHook API hooking library☆55Oct 5, 2022Updated 3 years ago
- My collection of battle-tested Aggressor Scripts for Cobalt Strike 4.0+☆1,107Apr 19, 2023Updated 3 years ago
- RCE exploit for Microsoft Exchange Server (CVE-2021-26855).☆22Apr 23, 2022Updated 4 years ago
- Using syscall to load shellcode, Evasion techniques☆26Jul 18, 2021Updated 5 years ago
- Nim Library for Offensive Security Development☆200Sep 4, 2023Updated 2 years ago
- Use hardware breakpoint to dynamically change SSN in run-time☆281Apr 10, 2024Updated 2 years ago
- A tool which bypasses AMSI (AntiMalware Scan Interface) and PowerShell CLM (Constrained Language Mode) and gives you a FullLanguage Power…☆821Mar 28, 2025Updated last year