Rostelecom-Red-Team / GoodbyeEDRLinks
☆81Updated 3 years ago
Alternatives and similar repositories for GoodbyeEDR
Users that are interested in GoodbyeEDR are comparing it to the libraries listed below
Sorting:
- bypass UAC even when configured to always notify user☆29Updated 4 years ago
- UAC_wenpon☆49Updated 3 years ago
- ☆74Updated 4 years ago
- A simple hidden vnc.☆34Updated 4 years ago
- bypass BeaconEye☆87Updated 4 years ago
- (Hellsgate|Halosgate|Tartarosgate)+Spoofing-Gate. Ensures that all systemcalls go through ntdll.dll☆44Updated 3 years ago
- 汇编语言编写Shellcode加载器源代码 https://payloads.online/archivers/2022-02-16/1/☆78Updated 3 years ago
- Kernel file/process/object tool☆69Updated 4 years ago
- This PoC uses two diferent technics for stealing the primary token from all running processes, showing that is possible to impersonate a…☆57Updated 4 years ago
- Defense Evasion & Bypass AntiVirus reference☆74Updated 4 years ago
- ☆52Updated 5 years ago
- CVE-2021-1675 (PrintNightmare)☆76Updated 4 years ago
- A work in progress of constructing a minimal http(s) beacon for Cobalt Strike.☆26Updated 3 years ago
- use aswArPot.sys to kill process☆68Updated 3 years ago
- A flexible tool that creates a minidump of the LSASS process☆14Updated 3 years ago
- Simple windows rpc server for research purposes only☆83Updated 3 years ago
- PrintNightmare , Local Privilege Escalation of CVE-2021-1675 or CVE-2021-34527☆59Updated 4 years ago
- ShellCodeLoader via DInvoke☆60Updated 4 years ago
- dump lsass tool☆38Updated 3 years ago
- DLL Unhooking☆13Updated 4 years ago
- Load the evilDLL from socket connection without touch disk☆16Updated 4 years ago
- StenographyShellcodeLoader☆43Updated 5 years ago
- power-kill is a project that kill protected processes (such as EDR or AV) by injecting shellcode into high privilege processes☆48Updated 4 years ago
- ☆74Updated 4 years ago
- Golang implementation of Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll;☆32Updated 3 years ago
- BOF/COFF obj file to PIC(shellcode). by golang☆39Updated 3 years ago
- ☆89Updated 3 years ago
- LOLBINs that inject a DLL into a given process ID.☆139Updated 3 years ago
- Exploits undocumented elevated COM interface ICMLuaUtil via process spoofing to edit registry then calls ColorDataProxy to trigger UAC b…☆142Updated 3 years ago
- 看起来叫BabyBypass,实际啥都会记一些☆16Updated 2 years ago