ShadowStrike A Windows EDR Platform
☆36Aug 7, 2026Updated this week
Alternatives and similar repositories for ShadowStrike
Users that are interested in ShadowStrike are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Stream your Windows system audio over LAN to any device directly through a browser, connected on the same network. No apps. No drivers. P…☆16Nov 6, 2025Updated 9 months ago
- low-level windows networking library using afd.sys sockets and schannel tls. bypasses winsock, winhttp, wininet and other high-level netw…☆17Jul 15, 2026Updated 3 weeks ago
- load arbitrary dlls, call any exported function, calls execute inside g0 as normal syscalls do from the traditional route, no syscall or …☆31May 4, 2026Updated 3 months ago
- Anti-Debugging (Self-Debugging)☆17Sep 6, 2025Updated 11 months ago
- 针对windows rootkit的一些检测,分别从进程、端口、文件这三个方面进行检测。☆21Jan 16, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A REALLY Danger Windows Driver, Turn Any threads Ring0!☆13Jul 20, 2026Updated 3 weeks ago
- Shellcode capable of bypassing EAF / IAF mitigations☆30Apr 11, 2023Updated 3 years ago
- Querying And Deleting Shadow Copies Using The IOCTL_VOLSNAP_QUERY_NAMES_OF_SNAPSHOTS & IOCTL_VOLSNAP_DELETE_SNAPSHOT IOCTLs☆22Aug 7, 2025Updated last year
- Reversed WintaPix Malware Source code | That targets countries in the Middle East and abuse KeServiceDescriptorTable(SSDT), persistence a…☆21Jul 6, 2024Updated 2 years ago
- Proof-of-Concept exploit for CVE-2026-32223☆21Apr 17, 2026Updated 3 months ago
- A Free Open sourced crypter that builds a output .NET .exe Stub (Updated whenever I feel like it)☆24Oct 18, 2025Updated 9 months ago
- DPAPI research and offensive tools☆17Feb 12, 2026Updated 5 months ago
- A simple Reset Survival PoC☆15Jan 25, 2026Updated 6 months ago
- ☆14Jul 19, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Simple KDMapper driver dumper. Unlike other dumpers, this dumper dumps the PE headers of the image too.☆18May 10, 2024Updated 2 years ago
- Cobaltstrike UDRL with memory evasion☆15May 16, 2024Updated 2 years ago
- Minimalistic HTTP(S) client for the NT kernel☆61Dec 1, 2025Updated 8 months ago
- KSE Shim Registration for abusing patching of IAT, driver callbacks, and IRP I/O packets.☆15Dec 12, 2025Updated 7 months ago
- An AVX Lifter for the Hex-Rays Decompiler + new instructions☆11Oct 14, 2022Updated 3 years ago
- An example of using Dynamic Invoke to Inject Shellcode using the Early Bird Method.☆15Dec 14, 2023Updated 2 years ago
- Select which local O/S to boot by asking a network server☆13Jul 4, 2018Updated 8 years ago
- From 2011: Quickly search for files in NTFS volumes parsing the Master File Table (MFT). A decent amount of how NTFS and MFT work was pai…☆28Oct 14, 2019Updated 6 years ago
- reverse engineering random malwares☆24Mar 12, 2026Updated 4 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Easily access open source food and nutritional data from the USDA.☆10Mar 17, 2018Updated 8 years ago
- Logging library for kernel drivers written for the Windows NT operating system.☆21Oct 17, 2025Updated 9 months ago
- A 64-bit ELF loader in C to avoid use of execve. Supports loading and executing statically linked non-PIE and PIE binaries on Linux.☆20Jan 5, 2026Updated 7 months ago
- LLVM-based compiler to create artificial software diversity to protect software from code-reuse attacks.☆18Sep 12, 2018Updated 7 years ago
- Return to a 32-bit environment in an x64 program and trigger a bound exception to communicate with the driver layer via KeRegisterBoundCa…☆24Nov 29, 2025Updated 8 months ago
- A custom implementation of the Nanomites protection technology for Windows executables (x86 and x64) originally introduced by Silicon Rea…☆43Jan 11, 2026Updated 6 months ago
- ☆38Sep 26, 2024Updated last year
- Windows Kernel API wrapper with simplified functions and enterprise driver extensions.☆35Jul 8, 2025Updated last year
- Toolkits for KPH (KSystemInformer) Dynamic Data .☆34Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Sanctum is an experimental proof-of-concept EDR, designed to detect modern malware techniques, above and beyond the capabilities of antiv…☆568Mar 24, 2026Updated 4 months ago
- Golang bindings for the Binary Ninja Arm64 Disassembler.☆14Mar 16, 2026Updated 4 months ago
- CVE-2026-46242☆18Jul 4, 2026Updated last month
- Yandex browser passwords and credit-cards decryption algorithm☆25Apr 8, 2025Updated last year
- Discord HTTP requests interception POC, including backup codes requests, for educational purposes only.☆23Jul 11, 2024Updated 2 years ago
- Renamed to Free EDR to avoid confusion with Comodo's project☆26May 29, 2023Updated 3 years ago
- 🔬 Guest execution and tracing using the Windows Hypervisor Platform☆58Mar 14, 2026Updated 4 months ago