TwoSevenOneT / IAmAntimalwareLinks
This tool helps inject code into the processes of Antivirus programs.
☆156Updated 3 months ago
Alternatives and similar repositories for IAmAntimalware
Users that are interested in IAmAntimalware are comparing it to the libraries listed below
Sorting:
- 7z exploit POC versions prior to 25.01☆33Updated 5 months ago
- ☆41Updated last year
- ☆68Updated 2 years ago
- Repository for the DEF CON 33 talk: Kill Chain Reloaded☆77Updated 5 months ago
- A tool that supports finding and abusing whitelisted programs to allow arbitrary file writing into the executable folder of Antivirus sof…☆80Updated 3 months ago
- ☆37Updated 3 weeks ago
- A dynamic HTTP/S stager that lets one shellcode loader be reused for different encrypted payloads - no rebuilds.☆19Updated 3 months ago
- AV/EDR killer using BYOVD technique☆43Updated last year
- A lightweight tool that injects a custom assembly proxy into a target process to silently bypass AMSI scanning by redirecting AmsiScanBuf…☆62Updated 8 months ago
- TeamViewer User to Kernel Elevation of Privilege PoC. CVE-2024-7479 and CVE-2024-7481. ZDI-24-1289 and ZDI-24-1290. TV-2024-1006.☆136Updated last year
- PoC for CVE-2025-22457 - A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Pulse Connect Secure, Ivan…☆71Updated 9 months ago
- WSUS Unauthenticated RCE☆169Updated 3 months ago
- Remote administration toolkit for windows, based on Hidden VNC: file manager, keystroke logger, powershell☆34Updated 2 months ago
- WinRAR 0day CVE-2025-8088 PoC RAR Archive☆45Updated 5 months ago
- ☆49Updated 2 months ago
- We found a way to DLL sideload with cleanmgr.exe☆96Updated 11 months ago
- Beacon Debugger☆55Updated last year
- CVE-2025-0282 is a critical vulnerability found in Ivanti Connect Secure, allowing Remote Command Execution (RCE) through a buffer overfl…☆52Updated last year
- Linux Process Injection via Seccomp Notifier☆81Updated last month
- Abusing SSRF to deliver an authenticated command injection payload☆30Updated 5 months ago
- Identifies LOLDrivers that are not blocked by the active HVCI policy — ideal for BYOVD scenarios.☆32Updated 3 weeks ago
- Ivanti Connect Secure IFT TLS Stack Overflow pre-auth RCE (CVE-2025-0282)☆31Updated last year
- Exploit for stack-based buffer overflow found in the conn-indicator binary in the TP-Link Archer AX50 router☆30Updated 3 months ago
- Exploit for CVE-2025-11001 or CVE-2025-11002☆147Updated 2 months ago
- gRPC client for the Merlin Server☆27Updated 9 months ago
- Proof-of-Concept for CVE-2024-21345☆76Updated last year
- EDRStartupHinder: A red team tool to prevent Antivirus and EDR from running.☆172Updated 3 weeks ago
- PoC for CVE-2025-0282: A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Ivanti Policy Secure, and Iv…☆49Updated last year
- ☆124Updated last year
- command control framework☆29Updated last week