Kudaes / Bin-Finder
Detect EDR's exceptions by inspecting processes' loaded modules
☆124Updated 10 months ago
Alternatives and similar repositories for Bin-Finder:
Users that are interested in Bin-Finder are comparing it to the libraries listed below
- ☆136Updated last month
- Rusty Impersonate☆94Updated last year
- ☆134Updated last year
- Simple BOF to read the protection level of a process☆114Updated last year
- An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution☆157Updated last month
- EDRSandblast-GodFault☆243Updated last year
- Adversary Emulation Framework☆61Updated 5 months ago
- An App Domain Manager Injection DLL PoC on steroids☆164Updated last year
- BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR☆73Updated 11 months ago
- Example code samples from our ScriptBlock Smuggling Blog post☆87Updated 7 months ago
- ☆121Updated 4 months ago
- A variation of ProcessOverwriting to execute shellcode on an executable's section☆147Updated last year
- A Rust port of LayeredSyscall — performs indirect syscalls while generating legitimate API call stack frames by abusing VEH.☆132Updated 2 months ago
- Port of Cobalt Strike's Process Inject Kit☆160Updated last month
- WTSImpersonator utilizes WTSQueryUserToken to steal user tokens by abusing the RPC Named Pipe "\\pipe\LSM_API_service"☆118Updated 6 months ago
- AzureAD beacon object files☆105Updated last month
- Implant drop-in for EDR testing☆131Updated last year
- 64-bit, position-independent implant template for Windows in Rust.☆103Updated 3 months ago
- ETW based POC to identify direct and indirect syscalls☆178Updated last year
- Two in one, patch lifetime powershell console, no more etw and amsi!☆84Updated 6 months ago
- Red teaming tool to dump LSASS memory, bypassing basic countermeasures.☆121Updated 2 weeks ago
- ☆136Updated 5 months ago
- This repo will contain the core detection, only for Cobaltstrike's leaked versions. Non-leaked version detections wont be shared☆88Updated last year
- ☆111Updated last year
- A web assembly (WASM) phishing lure generator based on pre-built templates and written in Rust with some GenAI assistance. W.A.L.K. aims …☆65Updated 4 months ago
- Lateral Movement☆122Updated last year
- Two new offensive techniques using Windows Fibers: PoisonFiber (The first remote enumeration & Fiber injection capability POC tool) Phan…☆215Updated 4 months ago
- A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge …☆172Updated last year
- Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctype…☆109Updated last year