AV Evasion Techniques
☆82Jul 28, 2022Updated 3 years ago
Alternatives and similar repositories for evasion
Users that are interested in evasion are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Windows Post-Exploitation tools wrapper☆12Jun 24, 2024Updated last year
- Linux Post-Exploitation tools wrapper☆20Mar 21, 2023Updated 3 years ago
- Use IronPython directly in your code without IronPython DLLs and dependencies☆12Jan 19, 2022Updated 4 years ago
- Patch AMSI and ETW☆252May 8, 2024Updated 2 years ago
- Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged☆89Jul 7, 2022Updated 3 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- MacroPhantom automates the process of generating XOR+Caesar encrypted shellcode and embedding it into VBA macros for Microsoft Office doc…☆22Mar 20, 2025Updated last year
- Proof-of-concept obfuscation toolkit for C# post-exploitation tools☆615Jul 22, 2022Updated 3 years ago
- PEN-300 collection to help you on your exam.☆708Feb 25, 2026Updated 2 months ago
- A repository with my notable code snippets for Offensive Security's PEN-300 (OSEP) course.☆1,434Jul 27, 2025Updated 9 months ago
- A new AMSI Bypass technique using .NET ALI Call Hooking.☆194Nov 15, 2022Updated 3 years ago
- random code snippets, useful for getting started☆123Nov 29, 2025Updated 5 months ago
- AspXVenom automates the process of generating encoded shellcode and embedding it into ASPX webshells, providing a smooth workflow for pen…☆19Mar 19, 2025Updated last year
- Do some DLL SideLoading magic☆92Sep 20, 2023Updated 2 years ago
- ☆19Jan 11, 2023Updated 3 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- C# havoc implant☆101Feb 12, 2023Updated 3 years ago
- ☆1,683Apr 14, 2025Updated last year
- Simple & Powerful PowerShell Script Obfuscator☆593May 13, 2025Updated 11 months ago
- Loads any C# binary in mem, patching AMSI + ETW.☆847Oct 3, 2021Updated 4 years ago
- Local privilege escalation from SeImpersonatePrivilege using EfsRpc.☆346Oct 17, 2022Updated 3 years ago
- ☆19Aug 10, 2022Updated 3 years ago
- This POC gives you the possibility to compile a .exe to completely avoid statically detection by AV/EPP/EDR of your C2-shellcode and down…☆258May 25, 2023Updated 2 years ago
- Fileless lateral movement tool that relies on ChangeServiceConfigA to run command☆1,633Jul 10, 2023Updated 2 years ago
- Bypass AMSI by patching AmsiScanBuffer☆283Jun 4, 2021Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- This repo contains some Amsi Bypass methods i found on different Blog Posts.☆2,155Nov 28, 2024Updated last year
- AutoMSF is a Python script designed for fast generation and deployment of multiple types of Meterpreter reverse_https payloads. Created t…☆19Mar 20, 2025Updated last year
- A windows token impersonation tool☆323Apr 19, 2023Updated 3 years ago
- A launcher to load a DLL with xored cobalt strike shellcode executed in memory through process hollowing technique☆28Nov 11, 2022Updated 3 years ago
- ☆26Aug 11, 2025Updated 8 months ago
- Easy peasy file uploads☆35Aug 29, 2025Updated 8 months ago
- Nim Library for Offensive Security Development☆202Sep 4, 2023Updated 2 years ago
- ☆72Aug 2, 2022Updated 3 years ago
- My collection of battle-tested Aggressor Scripts for Cobalt Strike 4.0+☆1,102Apr 19, 2023Updated 3 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- CVE's we discovered along the way☆17Oct 18, 2021Updated 4 years ago
- A C# port of the MinHook API hooking library☆55Oct 5, 2022Updated 3 years ago
- A tool which bypasses AMSI (AntiMalware Scan Interface) and PowerShell CLM (Constrained Language Mode) and gives you a FullLanguage Power…☆817Mar 28, 2025Updated last year
- Use hardware breakpoint to dynamically change SSN in run-time☆281Apr 10, 2024Updated 2 years ago
- RCE exploit for Microsoft Exchange Server (CVE-2021-26855).☆22Apr 23, 2022Updated 4 years ago
- Expeditus is a loader that executes shellcode on a target Windows system. It combines several offensive techniques in order to attempt to…☆13May 30, 2022Updated 3 years ago
- Using syscall to load shellcode, Evasion techniques☆27Jul 18, 2021Updated 4 years ago