Offensive-Panda / D3MPSECLinks
"D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system calls, randomized procedures, and prototype name obfuscation. Its primary purpose is to bypass both static and dynamic analysis techniques commonly employed by security measures.
☆28Updated last year
Alternatives and similar repositories for D3MPSEC
Users that are interested in D3MPSEC are comparing it to the libraries listed below
Sorting:
- Creation and removal of Defender path exclusions and exceptions in C#.☆33Updated 2 years ago
- lsassdump via RtlCreateProcessReflection and NanoDump☆84Updated last year
- Slides and POC demo for my talk at Divizion Zero on EDR evasion titled "Evasion Adventures"☆31Updated 3 years ago
- ☆59Updated last year
- This project is an EDRSandblast fork, adding some features and custom pieces of code.☆24Updated 2 years ago
- An Aggressor Script that utilizes NtCreateUserProcess to run binaries☆30Updated 11 months ago
- ☆32Updated 11 months ago
- A Cobalt Strike payload generator and lateral movement aggressor script which places Beacon shellcode into a custom shellcode loader☆45Updated last year
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆83Updated last year
- ☆61Updated 2 years ago
- .NET profiler DLL loading can be abused to make a legit .NET application load a malicious DLL using environment variables. This exploit i…☆47Updated last year
- Cobalt Strike UDRL for memory scanner evasion.☆52Updated 2 years ago
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆84Updated 2 weeks ago
- A simple PoC of injection shellcode into a remote process and get the output using namepipe☆44Updated 2 years ago
- DFSCoerce exe revisited version with custom authentication☆41Updated 2 years ago
- string/file/shellcode encryptor using AES/XOR☆11Updated 2 years ago
- Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials☆61Updated 8 months ago
- EmbedExeLnk by x86matthew modified by d4rkiZ☆42Updated 2 years ago
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆78Updated last year
- ☆109Updated 11 months ago
- ☆52Updated 3 months ago
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆51Updated last year
- ☆24Updated last year
- Windows Thread Pool Injection Havoc Implementation☆33Updated last year
- in-process powershell runner for BRC4☆48Updated 2 years ago
- ☆50Updated 6 months ago
- ☆74Updated last year
- ☆83Updated last year
- C++ tool and library for converting .bin files to shellcode in multiple output formats.☆34Updated 5 months ago
- I have documented all of the AMSI patches that I learned till now☆76Updated 2 months ago