Orange-Cyberdefense / EDRSnowblastLinks
This project is an EDRSandblast fork, adding some features and custom pieces of code.
☆23Updated 2 years ago
Alternatives and similar repositories for EDRSnowblast
Users that are interested in EDRSnowblast are comparing it to the libraries listed below
Sorting:
- An Aggressor Script that utilizes NtCreateUserProcess to run binaries☆30Updated 8 months ago
- EmbedExeLnk by x86matthew modified by d4rkiZ☆41Updated 2 years ago
- Creation and removal of Defender path exclusions and exceptions in C#.☆31Updated last year
- ☆29Updated 8 months ago
- yet another sleep encryption thing. also used the default github repo name for this one.☆69Updated 2 years ago
- Cobalt Strike UDRL for memory scanner evasion.☆52Updated last year
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆102Updated 2 years ago
- ☆37Updated 2 years ago
- ☆50Updated 3 months ago
- DLL proxy load example using the Windows thread pool API, I/O completion callback with named pipes, and C++/assembly☆62Updated last year
- Beacon Object Files (not Buffer Overflows)☆56Updated 2 years ago
- ☆24Updated last year
- ☆47Updated 2 years ago
- Example of using Sleep to create better named pipes.☆41Updated 2 years ago
- Cobalt Strike Beacon Object File to enable the webdav client service on x64 windows hosts☆22Updated 2 years ago
- Sleep Obfuscation☆45Updated 2 years ago
- A work in progress BOF/COFF loader in Rust☆50Updated 2 years ago
- A VSCode plugin to assist with BOF development.☆37Updated last year
- A method to execute shellcode using RegisterWaitForInputIdle API.☆55Updated 2 years ago
- A Cobalt Strike payload generator and lateral movement aggressor script which places Beacon shellcode into a custom shellcode loader☆42Updated last year
- ☆32Updated 6 months ago
- Using LNK files and user input simulation to start processes under explorer.exe☆25Updated last year
- DLL Exports Extraction BOF with optional NTFS transactions.☆83Updated 3 years ago
- Click Once + App Domain☆63Updated last year
- Rewrite to fit my needs☆31Updated last year
- miscellaneous codes☆34Updated 2 years ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆40Updated 2 years ago
- Slides and POC demo for my talk at Divizion Zero on EDR evasion titled "Evasion Adventures"☆30Updated 2 years ago
- havoc2nginx is a simple python script that converts Havoc Framework's yaotl malleable c2 profile to Nginx configuration file format. Most…☆12Updated 2 years ago
- A bunch of shenanigans using functions, VEH and more☆35Updated 4 months ago