Karmaz95 / evasion
AV EVASION TECHNIQUES
☆79Updated 2 years ago
Alternatives and similar repositories for evasion:
Users that are interested in evasion are comparing it to the libraries listed below
- A collection of code snippets built to assist with breaking chains.☆117Updated last year
- ☆32Updated 3 years ago
- A variety of AV evasion techniques written in C# for practice.☆89Updated 4 years ago
- Payload Generation Framework☆91Updated last year
- Code dump from PEN-300/OSEP updated 2022☆41Updated 2 years ago
- PoC to coerce authentication from Windows hosts using MS-WSP☆236Updated last year
- Attempt at Obfuscated version of SharpCollection☆206Updated 3 weeks ago
- A Python based ingestor for BloodHound☆83Updated 2 years ago
- The Elevate Kit demonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload.☆120Updated 4 years ago
- A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY☆83Updated 3 years ago
- SeRestorePrivilege to SYSTEM☆108Updated 3 years ago
- This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR …☆257Updated 2 years ago
- Determine if the WebClient Service (WebDAV) is running on a remote system☆137Updated last year
- Impacket is a collection of Python classes for working with network protocols.☆71Updated 8 months ago
- Identifies the bytes that Microsoft Defender flags on.☆84Updated 3 years ago
- ☆159Updated 6 months ago
- ☆111Updated last year
- ☆202Updated last year
- Impacket is a collection of Python classes for working with network protocols.☆281Updated 4 months ago
- ☆117Updated last month
- ☆79Updated 5 years ago
- CLI monitor for windows process- & file activity☆87Updated 4 years ago
- Shellcode generation and encoding utility☆22Updated 2 years ago
- Python based Bloodhound data converter from the legacy pre 4.1 format to 4.1+ format☆56Updated 2 years ago
- Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods☆111Updated last year
- PowerShell Constrained Language Mode Bypass☆262Updated 4 years ago
- Precompiled executable☆53Updated 2 months ago
- Patching AmsiOpenSession by forcing an error branching☆145Updated last year
- Python tool to Check running WebClient services on multiple targets based on @leechristensen☆273Updated 3 years ago
- The BackupOperatorToolkit contains different techniques allowing you to escalate from Backup Operator to Domain Admin☆174Updated 2 years ago