ProcessusT / Bypass-AV-DirectSyscalls
Scripts permettant de contourner la protection antivirale de Windows Defender via la technique de Direct Syscalls avec une injection de shellcode préalablement obfusqué avec un fonction XOR.
☆27Updated 2 years ago
Alternatives and similar repositories for Bypass-AV-DirectSyscalls:
Users that are interested in Bypass-AV-DirectSyscalls are comparing it to the libraries listed below
- Small project to facilitate creation of .lnk payloads☆65Updated 2 years ago
- A C2 framework built for my bachelors thesis☆55Updated 4 months ago
- A havoc UI python module to help in reporting and vulnerabilities to exploit on an internal network.☆12Updated last year
- Token Elevation to authorized user as SYSTEM or Domain Admins☆23Updated last year
- LSTAR - CobaltStrike Translated to EN☆13Updated last year
- PowerShell script to terminate protected processes such as anti-malware and EDRs.☆26Updated last year
- Bypass AMSI By Dividing files into multiple smaller files☆45Updated 2 years ago
- Scripts I use to deploy Havoc on Linode and setup categorization and SSL☆40Updated 10 months ago
- AMSI Bypass for powershell☆30Updated 2 years ago
- Exploits Scripts and other tools that are useful during Penetration-Testing or Red Team engagement☆64Updated 2 years ago
- Most Responder's configuration power in your hand.☆47Updated 2 months ago
- ☆47Updated 2 years ago
- Automated Evilginx phishlet creator Extension for Burpsuite☆46Updated 2 months ago
- a port of privkit bof for havoc☆23Updated last year
- A repository with my code snippets for research/education purposes.☆50Updated last year
- Situational Awareness script to identify how and where to run implants☆48Updated 3 months ago
- A PoC weaponising CustomXMLPart for hiding malware code inside of Office document structures.☆36Updated 2 years ago
- ShadowForge Command & Control - Harnessing the power of Zoom's API, control a compromised Windows Machine from your Zoom Chats.☆47Updated last year
- This is way to load a shellcode, and obfuscate it, so it avoids scantime detection.☆60Updated 8 months ago
- C# havoc implant☆100Updated 2 years ago
- Public repo of some woking evilginx phishlets☆30Updated 4 months ago
- Lifetime AMSI bypass.☆35Updated 9 months ago
- .bin file to shellcode convertor☆34Updated 8 months ago
- execute PE in memory Filelessly☆32Updated last month
- Inject RDPThief into memory with PowerShell.☆62Updated 2 months ago
- Cobalt strike CNA script to notify you via Discord whenever there is a new beacon.☆33Updated 2 years ago
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆47Updated 10 months ago
- Duplicate not owned Token from Running Process☆72Updated last year
- An impacket-lite cli tool that combines many useful impacket functions using a single session.☆47Updated last month
- Simple PoC Python agent to showcase Havoc C2's custom agent interface. Not operationally safe or stable. Released with accompanying blog …☆80Updated last year