CyberShield 2025 Intro to EDR Evasion Class
☆18Jun 3, 2025Updated last year
Alternatives and similar repositories for Intro-to-EDR-Evasion
Users that are interested in Intro-to-EDR-Evasion are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A simple to use single-include Windows API resolver☆22Jul 9, 2024Updated 2 years ago
- Situational Awareness script to identify how and where to run implants☆70Dec 6, 2024Updated last year
- BOF for extracting Edge credentials from the main browser process.☆50May 5, 2026Updated 3 months ago
- Dissecting and Defeating Ransomware's Evasion Tactics Defcon 32☆17Aug 9, 2024Updated 2 years ago
- Crystal Palace library for proxying Nt API calls via the Threadpool☆107Oct 18, 2025Updated 10 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Safe Harbor is a BOF that streamlines process reconnaissance for red team operations by identifying trusted, low-noise targets to maintai…☆81Oct 27, 2025Updated 9 months ago
- Secure Terminal CTF Challenge for DC31 Red Team Village☆19Aug 22, 2023Updated 2 years ago
- Cobalt Strike Beacon Object File (BOF) that obtain SYSTEM privilege with SeImpersonate privilege by passing a malicious IUnknwon object t…☆13Feb 4, 2024Updated 2 years ago
- Shellcode Loader Utilizing ETW Events☆66Feb 26, 2025Updated last year
- A Beacon Object File for decrypting Chrome App-Bound Encryption masterkeys in-memory via Cobalt Strike☆18Jul 14, 2025Updated last year
- A C++/Asm template for PIC/EXE/DLL malware☆24Aug 12, 2025Updated last year
- A Sublime Text plugin that allows for Nmap syntax highlighting☆13Sep 14, 2024Updated last year
- Example of using Sleep to create better named pipes.☆41Jul 25, 2023Updated 3 years ago
- A cheatsheet of commands used to pass the CARTP (Certified Azure Red Team Professional) exam.☆27May 4, 2023Updated 3 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- A Golang CLI for the MITRE ATT&CK Framework☆15Apr 28, 2025Updated last year
- A collection of sample code used in some experiments with Sliver C2☆17Mar 28, 2023Updated 3 years ago
- A tool for exploiting Kerberos tickets against system with Credential Guard enabled.☆15Sep 2, 2025Updated 11 months ago
- Regex based secret scanner for sccm deployment points sccmcontentlib$ shares. Find secrets automatically and download entire packages for…☆18Aug 13, 2025Updated last year
- Implementing Ghostly-Hollowing using tampered syscalls for remote PE injection☆75Dec 26, 2025Updated 7 months ago
- ☆52May 4, 2025Updated last year
- Simple HTTP async comms using standard GET/POST requests☆50Jul 30, 2026Updated 2 weeks ago
- Random BOFs for LDAP tradecraft☆73Sep 9, 2025Updated 11 months ago
- A python port of CCob's ThreadlessInject☆25Mar 18, 2023Updated 3 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- An easy way to convert BloodHound output files into data that can be imported into reporting software like Dradis and Plextrac. Built by …☆20Oct 15, 2020Updated 5 years ago
- ☆37Nov 8, 2024Updated last year
- Windows Portable Device COM BOF☆18Mar 30, 2026Updated 4 months ago
- XPN's RpcEnum but based on IDA instead of Ghidra☆21Aug 17, 2019Updated 7 years ago
- Citrix CVE-2023-4966 from assetnote modified for parallel and file handling☆11Oct 25, 2023Updated 2 years ago
- ☆39Mar 28, 2025Updated last year
- A small Aggressor script to help Red Teams identify foreign processes on a host machine☆89Jan 6, 2023Updated 3 years ago
- Aggressor script to automatically download and load an arsenal of open source and private Cobalt Strike tooling.☆47Aug 16, 2024Updated 2 years ago
- ☆50Jul 9, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- An improvement and a different approach to Mockingjay Self-Injection.☆35May 21, 2024Updated 2 years ago
- GoPhish-Deploy is an automated deployment script for the GoPhish phishing framework, configuring it with SSL and secure defaults.☆15Mar 20, 2025Updated last year
- Docker container for running CobaltStrike 4.7 and above☆25Mar 20, 2025Updated last year
- An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution☆194Nov 27, 2024Updated last year
- Bulk indicator VirusTotal lookups supporting file hashes, domains and IPs.☆13May 28, 2025Updated last year
- Monitoring tool to detect patterns or IOCs (strings, regex, VirusTotal) and alert you and your team via console, Telegram or SMS written …☆17Feb 17, 2026Updated 6 months ago
- A collection of utilities to help with analysis on the command line.☆18Aug 9, 2024Updated 2 years ago