Whenever PowerShell is launched, Notepad will also open. You can customize the script for educational purposes, but I emphasize that I do not take any responsibility for its use or any actions taken.
β12Apr 21, 2025Updated 11 months ago
Alternatives and similar repositories for Powershell-Persistance
Users that are interested in Powershell-Persistance are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A malicous Golang Packageβ15Apr 21, 2025Updated 11 months ago
- π | RubyRedOps is a repository for advanced Red Team techniques and offensive malware, focused on Rubyβ11Apr 21, 2025Updated 11 months ago
- Loads NTDLL, parses the PE file, extracts "Zw" functions, retrieves their System Service Numbers (SSNs), and prints each functionβs name,β¦β15Apr 21, 2025Updated 11 months ago
- Kill malawarebytes process. Can be ported to any programming language.β12Apr 21, 2025Updated 11 months ago
- Evilbytecode-Gate resolves Windows System Service Numbers (SSNs) using two methods: analyzing the Guard CF Table in ntdll.dll and parsingβ¦β26Apr 21, 2025Updated 11 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI β’ AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Malware development in Go, learn today, anti dynamic analysis & Static & sandboxes.β15Apr 21, 2025Updated 11 months ago
- Parent Process ID Spoofing, coded in CGo.β24Apr 21, 2025Updated 11 months ago
- A Documentation for my module PS2BAT, it converts Powershell Scripts to Batchfile ones.β11Apr 21, 2025Updated 11 months ago
- VBS-Obfuscator-GO is a Go-based tool designed for obfuscating VBScript (VBS) files. It transforms readable VBScript code into a less recoβ¦β39Apr 21, 2025Updated 11 months ago
- (EDR) Dll Unhooking = kernel32.dll, kernelbase.dll, ntdll.dll, user32.dll, apphelp.dll, msvcrt.dll.β51May 22, 2025Updated 10 months ago
- Pattern-based AMSI bypass that patches AMSI.dll in memory by modifying comparison values, conditional jumps, and function prologues to neβ¦β28May 13, 2025Updated 10 months ago
- PhantomDelay is a precise delay function that uses the Windows high resolution performance counter to pause your program for a specified β¦β19May 8, 2025Updated 11 months ago
- β21Jan 8, 2026Updated 3 months ago
- Lifetime AMSI bypass.β36Apr 21, 2025Updated 11 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI β’ AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Ransomware written in go, encrypt - decrypt.β30Apr 27, 2025Updated 11 months ago
- Go Based Crypter That Can Bypass Any Kinds Of Antivirus Products, payload crypter supports over 4 programming languages.β61Apr 27, 2025Updated 11 months ago
- Measures average CPU cycles for the CPUID instruction to detect if the code is running in a VM by comparing against a threshold.β22Apr 21, 2025Updated 11 months ago
- Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package.β80Apr 27, 2025Updated 11 months ago
- GolangStyle, best looking go library.β13Apr 21, 2025Updated 11 months ago
- Go keylogger for Windows, logging keyboard input to a file using Windows API functions, and it is released under the Unlicense.β29Apr 21, 2025Updated 11 months ago
- This is way to load a shellcode, and obfuscate it, so it avoids scantime detection.β97Apr 27, 2025Updated 11 months ago
- Unhook Ntdll.dll, Go & C++.β33Apr 21, 2025Updated 11 months ago
- A mutliple tactics to execute shellcode in go :}β25Apr 21, 2025Updated 11 months ago
- 1-Click AI Models by DigitalOcean Gradient β’ AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click and start building anything your business needs.
- Bypasses AMSI protection through remote memory patching and parsing technique.β54May 12, 2025Updated 10 months ago
- Eset-Unload is a C++ tool that interacts with a process's loaded modules to identify and unload the ebehmoni.dll module, typically found β¦β12Apr 21, 2025Updated 11 months ago
- Bypassing Major EDR's with staged shellcode, custom getmodulehandleW and getprocaddress, veh syscalls & more.β30Apr 21, 2025Updated 11 months ago
- β18Jun 25, 2024Updated last year
- π§ C# UAC Bypass technique using mock directories π§β28Jul 27, 2022Updated 3 years ago
- Exploit POC for CVE-2024-22026 affecting Ivanti EPMM "MobileIron Core"β15May 15, 2024Updated last year
- Hook system calls on Windows by using Kaspersky's hypervisorβ17Dec 25, 2024Updated last year
- golang decryption poc of the new app bound encryption introduced in chrome version 127.β22Nov 4, 2024Updated last year
- Generate AES128 and AES256 Kerberos keys from a given username, password, and realmβ18Sep 18, 2024Updated last year
- Wordpress hosting with auto-scaling on Cloudways β’ AdFully Managed hosting built for WordPress-powered businesses that need reliable, auto-scalable hosting. Cloudways SafeUpdates now available.
- kASLR bypass technique on Intel CPUs.β32May 18, 2025Updated 10 months ago
- Reproducing Spyboy technique, which involves terminating all EDR/XDR/AVs processes by abusing the zam64.sys driverβ292Apr 21, 2025Updated 11 months ago
- Examples how to use a Assm (Assembly) in a go.β24Apr 21, 2025Updated 11 months ago
- Yet another shellcode loader - but a sneaky oneβ26Apr 16, 2025Updated 11 months ago
- NailaoLoader: Hiding Execution Flow via Patchingβ23Feb 27, 2025Updated last year
- Two in one, patch lifetime powershell console, no more etw and amsi!β103Apr 27, 2025Updated 11 months ago
- β39Feb 26, 2025Updated last year