MirekVales / MVsDotNetAMSIClientLinks
🛡️ Convenient .NET Library for Invoking Antimalware Scan Interface (AMSI)
☆19Updated 3 years ago
Alternatives and similar repositories for MVsDotNetAMSIClient
Users that are interested in MVsDotNetAMSIClient are comparing it to the libraries listed below
Sorting:
- A library to hook functions !☆19Updated 4 years ago
- Hide code from dnSpy and other C# spying tools☆42Updated 5 years ago
- Unlock files and folders☆14Updated 3 years ago
- 32 bit process inject shellcode to 32 bit process and 64 bit process☆35Updated 2 years ago
- ☆11Updated 2 years ago
- A lightweight .NET assembly dependency merger that uses dnLib and 7zip's LZMA SDK for compressing dependant assemblies.☆105Updated last year
- Detect BypassUAC using AMSI☆29Updated 10 months ago
- Tunnellable HTTP/HTTPS socks5 proxy written in C#☆27Updated 4 years ago
- 简单版的PE加载器☆12Updated 5 years ago
- A small shellcode loader library written in C#☆48Updated 4 years ago
- My personal shellcode loader☆32Updated 2 years ago
- ☆20Updated 2 years ago
- A C Implementation for using a new method to invoke undetectable indirect syscalls☆20Updated last month
- Just another version of the custom stack call from Proxy-Function-Calls-For-ETwTI☆34Updated 2 years ago
- A proof of concept of real custom GetProcAddress and GetModuleBaseAddress☆21Updated 3 years ago
- This PoC uses two diferent technics for stealing the primary token from all running processes, showing that is possible to impersonate a…☆57Updated 4 years ago
- Stack integrity verification to Detect SleepMask or CallStack Spoofer☆39Updated 5 months ago
- Without closing windows defender, to make defender useless by removing its token privileges and lowering the token integrity.☆31Updated 3 years ago
- Load a fresh new copy of ntdll.dll via file mapping to bypass API inline hook.☆62Updated 4 years ago
- Windows Service with the implementation of the Process hollowing technique to run shellcode☆14Updated 2 years ago
- C# API for Nidhogg rootkit☆20Updated last year
- Herpaderply Hollowing - a PE injection technique, hybrid between Process Hollowing and Process Herpaderping☆65Updated 3 years ago
- Cobaltstrike UDRL with memory evasion☆13Updated last year
- A collection of weird ways to execute unmanaged code in .NET☆174Updated 4 years ago
- Windows Kernel Knowledge && Collect Resources on the wire && Nothing innovation by myself &&☆61Updated this week
- Work with eBPF on Windows☆42Updated 10 months ago
- C# Utilities for Windows Notification Facility☆159Updated 8 months ago
- Change hash for a signed pe☆16Updated 2 years ago
- AV/EDR killer using BYOVD technique☆43Updated last year
- ProcessHollowing via csharp☆13Updated 4 years ago