Rostelecom-Red-Team / GoodbyeEDR
☆79Updated 3 years ago
Alternatives and similar repositories for GoodbyeEDR:
Users that are interested in GoodbyeEDR are comparing it to the libraries listed below
- bypass UAC even when configured to always notify user☆29Updated 3 years ago
- ☆73Updated 3 years ago
- UAC_wenpon☆48Updated 3 years ago
- (Hellsgate|Halosgate|Tartarosgate)+Spoofing-Gate. Ensures that all systemcalls go through ntdll.dll☆42Updated 2 years ago
- 汇编语言编写Shellcode加载器源代码 https://payloads.online/archivers/2022-02-16/1/☆79Updated 2 years ago
- ShellCodeLoader via DInvoke☆52Updated 3 years ago
- A simple hidden vnc.☆32Updated 3 years ago
- use aswArPot.sys to kill process☆67Updated 2 years ago
- Kernel file/process/object tool☆64Updated 3 years ago
- A Cobalt Strike memory evasion loader for redteamers☆95Updated last year
- Beacon Object File implementation of pwn1sher's KillDefender☆65Updated 2 years ago
- power-kill is a project that kill protected processes (such as EDR or AV) by injecting shellcode into high privilege processes☆46Updated 3 years ago
- ☆40Updated 3 years ago
- Section Mapping Process Injection modified with SysWhisper2 (sw2-secinject): Cobalt Strike BOF☆41Updated 2 years ago
- frida based script which automates the process of discovering and exploiting DLL Hijacks in target binaries. The discovered binaries can …☆50Updated last year
- Imitate CobaltStrike's Shellcode Generation☆3Updated 2 years ago
- PrintNightmare , Local Privilege Escalation of CVE-2021-1675 or CVE-2021-34527☆58Updated 3 years ago
- A wrapper of ldap_shell.py module which in ntlmrelayx☆62Updated 2 years ago
- creddump bypass AV☆41Updated 4 years ago
- cmd2shellcode☆78Updated 3 years ago
- CVE-2021-42287/CVE-2021-42278 exploits in powershell☆37Updated 2 years ago
- my learning case about windows☆21Updated 2 years ago
- It stinks☆101Updated 2 years ago
- Windows Kernel Knowledge && Collect Resources on the wire && Nothing innovation by myself &&☆54Updated 2 weeks ago
- Windows Defender VDM lua collections☆48Updated 2 years ago
- bypass BeaconEye☆88Updated 3 years ago
- 用于Dump指定进程的内存,主要利用静默退出机制(SilentProcessExit)和Windows API(MiniDumpW)实现☆25Updated 3 years ago
- A work in progress of constructing a minimal http(s) beacon for Cobalt Strike.☆18Updated 2 years ago
- Golang implementation of Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll;☆31Updated 2 years ago