Kudaes / Bin-Finder
Detect EDR's exceptions by inspecting processes' loaded modules
☆129Updated last year
Alternatives and similar repositories for Bin-Finder:
Users that are interested in Bin-Finder are comparing it to the libraries listed below
- Rusty Impersonate☆95Updated last year
- Adversary Emulation Framework☆98Updated 9 months ago
- ☆136Updated last year
- ☆154Updated 4 months ago
- Simple BOF to read the protection level of a process☆114Updated last year
- Windows Persistence IT-Security☆97Updated 2 months ago
- Implant drop-in for EDR testing☆138Updated last year
- ☆154Updated 9 months ago
- POC for frustrating/defeating Malware Analysts☆154Updated 2 years ago
- A Rust port of LayeredSyscall — performs indirect syscalls while generating legitimate API call stack frames by abusing VEH.☆143Updated 6 months ago
- Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctype…☆116Updated last year
- A variation of ProcessOverwriting to execute shellcode on an executable's section☆148Updated last year
- Massayo is a small proof-of-concept Rust library which removes AV/EDR hooks in a given system DLL☆65Updated 2 years ago
- This repo will contain the core detection, only for Cobaltstrike's leaked versions. Non-leaked version detections wont be shared☆89Updated last year
- An App Domain Manager Injection DLL PoC on steroids☆171Updated last year
- ☆105Updated 3 months ago
- Do some DLL SideLoading magic☆84Updated last year
- A BOF to enumerate system process, their protection levels, and more.☆116Updated 5 months ago
- AzureAD beacon object files☆118Updated 4 months ago
- Your syscall factory☆121Updated 2 months ago
- Port of Cobalt Strike's Process Inject Kit☆175Updated 5 months ago
- RDLL for Cobalt Strike beacon to silence sysmon process☆88Updated 2 years ago
- Simple EDR that injects a DLL into a process to place a hook on specific Windows API☆91Updated last year
- ☆126Updated 8 months ago
- ☆184Updated last year
- ☆122Updated last year
- Tool for viewing NTDS.dit☆161Updated last month
- BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR☆76Updated last year
- A tool for converting SysWhispers3 syscalls for use with Nim projects☆146Updated 2 years ago
- Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar☆130Updated 8 months ago