Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination IP addresses are parsed based on the server name in TLS Client Hello packet and the provided blocked server name (or blocked string) list in the file.
☆139Jul 23, 2024Updated 2 years ago
Alternatives and similar repositories for edr_blocker
Users that are interested in edr_blocker are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆30Jul 26, 2024Updated 2 years ago
- Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry☆477Aug 2, 2024Updated 2 years ago
- Generic PE loader for fast prototyping evasion techniques☆246Jul 2, 2024Updated 2 years ago
- ☆99Sep 1, 2024Updated 2 years ago
- Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!☆601Aug 17, 2026Updated last month
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- ☆146Oct 29, 2024Updated last year
- ApexLdr is a DLL Payload Loader written in C☆115Jul 17, 2024Updated 2 years ago
- Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR …☆312Jul 31, 2024Updated 2 years ago
- ☆110Aug 21, 2024Updated 2 years ago
- Remotely Enumerate sessions using undocumented Windows Station APIs☆117Aug 21, 2024Updated 2 years ago
- A new technique that can be used to bypass memory scanners. This can be useful in hiding problematic code (such as reflective loaders imp…☆359Oct 7, 2024Updated last year
- A command and control framework written in rust.☆390Aug 12, 2026Updated last month
- Abusing Windows fork API and OneDrive.exe process to inject the malicious shellcode without allocating new RWX memory region.☆293May 27, 2024Updated 2 years ago
- Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP.☆249Jun 11, 2024Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Identify common EDR processes, directories, and services. Simple BOF of Invoke-EDRChecker.☆135Oct 4, 2024Updated last year
- Proxll is a tool designed to simplify the generation of proxy DLLs while addressing common conflicts related to windows.h☆41Oct 8, 2024Updated last year
- BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions☆361Nov 19, 2024Updated last year
- ☆122Oct 9, 2023Updated 2 years ago
- Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.☆325Apr 12, 2024Updated 2 years ago
- Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths☆365Aug 11, 2024Updated 2 years ago
- Section-based payload obfuscation technique for x64☆63Aug 8, 2024Updated 2 years ago
- ☆126Sep 1, 2024Updated 2 years ago
- A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfve…☆598Jun 12, 2024Updated 2 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- HookChain: A new perspective for Bypassing EDR Solutions☆612Jan 5, 2025Updated last year
- An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer☆552Feb 13, 2024Updated 2 years ago
- Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird …☆810Jan 26, 2026Updated 7 months ago
- ☆51Jun 12, 2026Updated 3 months ago
- DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely☆396Dec 13, 2024Updated last year
- Local & remote Windows DLL Proxying☆171Jun 17, 2024Updated 2 years ago
- A VSCode plugin to assist with BOF development.☆36Aug 14, 2024Updated 2 years ago
- A PoC of the ContainYourself research presented in DEFCON 31, which abuses the Windows containers framework to bypass EDRs.☆318Aug 31, 2023Updated 3 years ago
- Execute commands in other Sessions☆93Jul 29, 2024Updated 2 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Inject DLLs into the explorer process using icons☆415May 18, 2025Updated last year
- TypeLib persistence technique☆152Oct 22, 2024Updated last year
- ☆60Oct 24, 2024Updated last year
- A POC to disable TamperProtection and other Defender / MDE components☆259Jun 6, 2024Updated 2 years ago
- Version 2 - A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders …☆102Mar 27, 2025Updated last year
- Process injection alternative☆405Sep 6, 2024Updated 2 years ago
- Slides and Codes used for the workshop Red Team Infrastructure Automation☆192Apr 14, 2024Updated 2 years ago