Ryze-T / EdrKiller
☆89Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for EdrKiller
- more conveniently Visual-Studio-BOF-template☆53Updated last year
- Shellcode Reductio Entropy Tools☆63Updated last year
- 免杀计划任务进行权限维持,过主流杀软。 A schtask tool bypass anti-virus☆66Updated 2 years ago
- Invoke-Obfuscation-Bypass + PS2EXE 过主流杀软☆52Updated 3 years ago
- ☆46Updated 3 years ago
- Cobalt Strike BOF that Add a user to localgroup by samr☆123Updated last year
- 替代PrintBug用于本地提权的新方式,主要利用MS-EFSR协议中的接口函数 借鉴了Potitpotam中对于EFSR协议的利用,实现了本地提权的一系列方式 Drawing on the use of the EFSR protocol in Potitpotam, …☆148Updated 2 years ago
- Binary Hollowing☆54Updated 2 months ago
- Magical obfuscator, supports obfuscating EXE, BOF, and ShellCode.☆78Updated this week
- ReturnGate, just like HellsGate.☆65Updated 2 years ago
- Resolve the issue of DLLmain function in white and black DLLs hanging when calling shellcode☆110Updated 5 months ago
- CobaltStrike4.5 Sleeve解密文件,搬砖加一点点修改, 仅作备份使用.☆30Updated 2 years ago
- 关于RPC一些绕EDR的tips☆158Updated last year
- 通过WindowsAPI获取用户凭证,并保存到文件中☆193Updated 5 months ago
- A Mimikatz For Only Extracting Login Passwords.(Bypasses Most AV's)☆59Updated 2 years ago
- CVE-2020-1472 C++☆83Updated 2 years ago
- Red team tool designed for quickly identifying hijackable programs, evading antivirus software, and EDR (Endpoint Detection and Response)…☆59Updated 6 months ago
- vehsyscall:a syscall project that may bypass EDR☆46Updated 8 months ago
- Cobalt Strike 二开项目☆177Updated last year
- ☆38Updated last year
- Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from mem…☆33Updated 6 months ago
- Amaterasu terminates, or inhibits, protected processes such as application control and AV/EDR solutions by leveraging the Sysinternals Pr…☆69Updated 8 months ago
- ☆101Updated 2 years ago
- command execute without 445 port☆51Updated 2 years ago
- BOF implementation of delete self poc that delete a locked executable or a currently running file from disk by its pid, path, or the curr…☆67Updated last year
- impacket编程手册☆98Updated last year
- Efficient RAT signature locator for bypassing AV/EDR, supporting static scanning and memory scanning.☆16Updated 3 weeks ago
- Alternative Shellcode Execution Via Callbacks Rewrite In C#☆87Updated last year