Ondrik8 / byPass_AV
☆148Updated 3 years ago
Alternatives and similar repositories for byPass_AV:
Users that are interested in byPass_AV are comparing it to the libraries listed below
- A Nim implementation of reflective PE-Loading from memory☆278Updated 7 months ago
- This POC gives you the possibility to compile a .exe to completely avoid statically detection by AV/EPP/EDR of your C2-shellcode and down…☆246Updated last year
- BOF implementation of @_EthicalChaos_'s ThreadlessInject project. A novel process injection technique with no thread creation, released a…☆378Updated last year
- This repo contains : simple shellcode Loader , Encoders (base64 - custom - UUID - IPv4 - MAC), Encryptors (AES), Fileless Loader (Winhttp…☆416Updated last year
- EarlyBird process hollowing technique (BOF) - Spawns a process in a suspended state, inject shellcode, hijack main thread with APC, and e…☆280Updated 2 years ago
- Shellcode Loader with Indirect Dynamic syscall Implementation , shellcode in MAC format, API resolving from PEB, Syscall calll and syscal…☆310Updated last year
- A little tool to play with the Seclogon service☆312Updated 2 years ago
- A C2 framework for initial access in Go☆180Updated 2 years ago
- Dump the memory of any PPL with a Userland exploit chain☆333Updated 2 years ago
- WIP shellcode loader in nim with EDR evasion techniques☆212Updated 3 years ago
- Windows Local Privilege Escalation via CdpSvc service (Writeable SYSTEM path Dll Hijacking)☆254Updated 2 years ago
- Cobalt Strike User-Defined Reflective Loader with AV/EDR Evasion in mind☆449Updated last year
- Various Cobalt Strike BOFs☆634Updated 2 years ago
- A BOF to automate common persistence tasks for red teamers☆274Updated 2 years ago
- Shellcode Loader Implementing Indirect Dynamic Syscall , API Hashing, Fileless Shellcode retrieving using Winsock2☆292Updated last year
- CaveCarver - PE backdooring tool which utilizes and automates code cave technique☆225Updated 2 years ago
- A Visual Studio template used to create Cobalt Strike BOFs☆304Updated 3 years ago
- A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!☆325Updated 9 months ago
- A Beacon Object File (BOF) template for Visual Studio☆189Updated last month
- A Stealthy Lsass Dumper - can abuse ProcExp152.sys driver to dump PPL Lsass, no dbghelp.lib calls.☆319Updated 2 years ago
- Payload Loader With Evasion Features☆316Updated 2 years ago
- C# Reflective loader for unmanaged binaries.☆430Updated 2 years ago
- x64 Assembly HalosGate direct System Caller to evade EDR UserLand hooks☆207Updated 2 years ago
- Cobalt Strike BOF - Bypass AMSI in a remote process with code injection.☆378Updated 2 years ago
- Remote Shellcode Injector☆213Updated last year
- A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC☆365Updated 2 years ago
- Get fresh Syscalls from a fresh ntdll.dll copy☆230Updated 3 years ago
- TartarusGate, Bypassing EDRs☆580Updated 3 years ago
- C++ self-Injecting dropper based on various EDR evasion techniques.☆370Updated last year
- (Demo) 3rd party agent for Havoc☆138Updated last year