ProcessusT / CobaltStrikeBypassDefender
A launcher to load a DLL with xored cobalt strike shellcode executed in memory through process hollowing technique
☆25Updated 2 years ago
Alternatives and similar repositories for CobaltStrikeBypassDefender:
Users that are interested in CobaltStrikeBypassDefender are comparing it to the libraries listed below
- "D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system c…☆24Updated 4 months ago
- A small Aggressor script to help Red Teams identify foreign processes on a host machine☆83Updated 2 years ago
- Create Anti-Copy DRM Malware☆51Updated 5 months ago
- Classic Process Injection with Memory Evasion Techniques implemantation☆66Updated last year
- This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hol…☆70Updated 11 months ago
- Just another Process Injection using Process Hollowing technique.☆16Updated last year
- NativePayload_PE1/PE2 , Injecting Meterpreter Payload bytes into local Process via Delegation Technique + in-memory with delay Changing R…☆57Updated last year
- Exploits Scripts and other tools that are useful during Penetration-Testing or Red Team engagement☆62Updated 2 years ago
- API Hammering with C++20☆44Updated 2 years ago
- This code example allows you to create a malware.exe sample that can be run in the context of a system service, and could be used for loc…☆51Updated last year
- PDF Icon File Type Spoofer☆13Updated 6 months ago
- Red Team Operation's Defense Evasion Technique.☆52Updated 7 months ago
- ☆48Updated 3 months ago
- This project is an EDRSandblast fork, adding some features and custom pieces of code.☆21Updated last year
- Unhook Ntdll.dll, Go & C++.☆17Updated 6 months ago
- 「⚙️」Detect which native Windows API's (NtAPI) are being hooked☆38Updated last month
- ☆36Updated last year
- C++ Staged Shellcode Loader with Evasion capabilities.☆73Updated 3 months ago
- C++ Code to perform a MiniDump of lsass.exe☆33Updated last year
- ☆18Updated 3 months ago
- Shellcode Loader using indirect syscalls☆14Updated last year
- PowerShell script to terminate protected processes such as anti-malware and EDRs.☆27Updated last year
- AMSI Bypass for powershell☆30Updated 2 years ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆46Updated 11 months ago
- Simple PoC to locate hooked functions by EDR in ntdll.dll☆36Updated last year
- a variety of tools,scripts and techniques developed and shared with different programming languages by 0xsp Lab☆62Updated last month
- Rex Shellcode Loader for AV/EDR evasion☆29Updated 9 months ago
- MS Office and Windows HTML RCE (CVE-2023-36884) - PoC and exploit☆37Updated last year
- Just another ntdll unhooking using Parun's Fart technique☆73Updated last year
- ☆19Updated 2 years ago