Checks running processes, process metadata, Dlls loaded into your current process and the each DLLs metadata, common install directories, installed services and each service binaries metadata, installed drivers and each drivers metadata, all for the presence of known defensive products such as AV's, EDR's and logging tools.
☆755Feb 24, 2026Updated 6 months ago
Alternatives and similar repositories for SharpEDRChecker
Users that are interested in SharpEDRChecker are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Checks running processes, process metadata, Dlls loaded into your current process and the each DLLs metadata, common install directories,…☆281Oct 9, 2023Updated 2 years ago
- A method of bypassing EDR's active projection DLL's by preventing entry point exection☆1,168Mar 31, 2021Updated 5 years ago
- .Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py☆613Feb 16, 2023Updated 3 years ago
- StandIn is a small .NET35/45 AD post-exploitation toolkit☆875Dec 2, 2023Updated 2 years ago
- The Hunt for Malicious Strings☆1,416May 13, 2025Updated last year
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or pro…☆273May 3, 2023Updated 3 years ago
- Fork of SafetyKatz that dynamically fetches the latest pre-compiled release of Mimikatz directly from gentilkiwi GitHub repo, runtime pat…☆885Mar 29, 2021Updated 5 years ago
- A .NET Runtime for Cobalt Strike's Beacon Object Files☆784Sep 4, 2024Updated 2 years ago
- SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GP…☆1,354Dec 15, 2020Updated 5 years ago
- Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS head…☆597Jul 26, 2021Updated 5 years ago
- Fileless lateral movement tool that relies on ChangeServiceConfigA to run command☆1,664Jul 10, 2023Updated 3 years ago
- Collection of beacon BOF written to learn windows and cobaltstrike☆360Feb 24, 2023Updated 3 years ago
- Porting of mimikatz sekurlsa::logonpasswords, sekurlsa::ekeys and lsadump::dcsync commands☆1,019Nov 7, 2021Updated 4 years ago
- Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019☆1,841Sep 4, 2024Updated 2 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- ☆668Nov 17, 2021Updated 4 years ago
- ScareCrow - Payload creation framework designed around EDR bypass.☆2,888Aug 18, 2023Updated 3 years ago
- ☆1,538Aug 11, 2023Updated 3 years ago
- OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at s…☆544Sep 18, 2022Updated 4 years ago
- Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensi…☆4,702Jan 10, 2025Updated last year
- LSASS memory dumper using direct system calls and API unhooking.☆1,595Jan 5, 2021Updated 5 years ago
- Open-Source Shellcode & PE Packer☆2,135Feb 3, 2024Updated 2 years ago
- Situational Awareness commands implemented using Beacon Object Files☆1,886Aug 17, 2026Updated last month
- .NET IPv4/IPv6 machine-in-the-middle tool for penetration testers☆814Aug 28, 2022Updated 4 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Evading WinDefender ATP credential-theft☆254Dec 2, 2019Updated 6 years ago
- C# implementation of harmj0y's PowerView☆1,108Mar 22, 2024Updated 2 years ago
- Whisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, …☆957Nov 11, 2024Updated last year
- A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certifica…☆878Mar 20, 2023Updated 3 years ago
- C2concealer is a command line tool that generates randomized C2 malleable profiles for use in Cobalt Strike.☆1,122Apr 13, 2026Updated 5 months ago
- "Golden" certificates☆714Aug 17, 2024Updated 2 years ago
- Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks b…☆464Mar 8, 2023Updated 3 years ago
- Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain☆384Sep 20, 2025Updated last year
- Collection of Offensive C# Tooling☆1,471Feb 6, 2023Updated 3 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Retrieves exported functions from a legitimate DLL and generates a proxy DLL source code/template for DLL proxy loading or sideloading☆920Jul 21, 2020Updated 6 years ago
- Enumerate and disable common sources of telemetry used by AV/EDR.☆864Mar 11, 2021Updated 5 years ago
- InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assem…☆768Jul 22, 2023Updated 3 years ago
- ☆2,205Apr 3, 2026Updated 5 months ago
- Loads any C# binary in mem, patching AMSI + ETW.☆853Oct 3, 2021Updated 4 years ago
- .NET Project for performing Authenticated Remote Execution☆409Feb 8, 2023Updated 3 years ago
- SharpWMI is a C# implementation of various WMI functionality.☆767Jan 15, 2021Updated 5 years ago