Windows Defender Manager is a tool that helps stop Windows Defender. It works with the Antimalware Service Executable of all versions of Windows 10 and Windows 11.
☆44Jan 18, 2025Updated last year
Alternatives and similar repositories for Windows-Defender-Manager
Users that are interested in Windows-Defender-Manager are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Automatically deploying Mythic C2 in Azure using Terraform☆21Jul 3, 2026Updated 2 weeks ago
- EDRStartupHinder: A red team tool to prevent Antivirus and EDR from running.☆193May 23, 2026Updated last month
- Beacon Object File (BOF) for identifying dependent child services of a given parent.☆19Jun 20, 2025Updated last year
- Automated script for obfuscating, rebranding and renaming the Havoc C2 Framework to evade AV/EDR and C2 hunters.☆48Aug 13, 2025Updated 11 months ago
- This tool helps inject code into the processes of Antivirus programs.☆189May 23, 2026Updated last month
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.☆857May 23, 2026Updated last month
- SVG Analysis and generation tools for commonly seen SVG attachment phishing☆57Sep 24, 2025Updated 9 months ago
- This is the loader that supports running a program with Protected Process Light (PPL) protection functionality.☆301May 23, 2026Updated last month
- NSecSoftBYOVD POC☆61Feb 12, 2026Updated 5 months ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago
- Execute shellcode via ASPNET compiler☆61Oct 2, 2025Updated 9 months ago
- Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass☆144Jan 29, 2026Updated 5 months ago
- Run PowerShell command without invoking powershell.exe☆27Apr 9, 2026Updated 3 months ago
- Step-by-step documentation on how to decrypt SCCM database secrets offline☆50Oct 20, 2025Updated 9 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A C# PE loader for x64 and x86 PE files.☆56Mar 9, 2026Updated 4 months ago
- PowerShell tool for auditing Microsoft Entra ID Conditional Access policies and MFA compliance☆45Aug 2, 2025Updated 11 months ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆120Dec 21, 2025Updated 6 months ago
- Dump LSASS process in Task Manager without triggering Defender.☆18Apr 6, 2023Updated 3 years ago
- Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading …☆167Feb 14, 2026Updated 5 months ago
- The tool used to clone the digital signatures of legitimate programs☆58Oct 11, 2025Updated 9 months ago
- Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)☆107Apr 4, 2026Updated 3 months ago
- Obex – Blocking unwanted DLLs in user mode☆279Sep 18, 2025Updated 10 months ago
- Cobaltstrike Reflective Loader with Synthetic Stackframe☆193Jan 17, 2026Updated 6 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Manage Shadows Copies via the VSS API using C#, C++, Crystal or Python. Working on Windows 11☆85Jan 26, 2026Updated 5 months ago
- A Proof-of-Concept implementation of Reflective DLL Injection (RDI) specifically for Windows on ARM64. Demonstrates PEB access via the x1…☆37May 30, 2025Updated last year
- SafeHarbor revamped with Direct Syscalls using InlineWhispers3☆15Feb 16, 2026Updated 5 months ago
- A powerful Windows command-line tool for analyzing and searching ETW (Event Tracing for Windows) provider permissions from the Windows re…☆65Jul 29, 2025Updated 11 months ago
- The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencie…☆180Sep 3, 2025Updated 10 months ago
- ☆31Aug 13, 2025Updated 11 months ago
- A tool that supports finding and abusing whitelisted programs to allow arbitrary file writing into the executable folder of Antivirus sof…☆92May 3, 2026Updated 2 months ago
- Just another EDR killer☆140Jan 21, 2026Updated 6 months ago
- Baseline a Windows System against LOLBAS☆78Jun 5, 2026Updated last month
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Request device ticket/token using the device's MSA☆37Aug 25, 2025Updated 10 months ago
- Cobalt Strike UDC2 implementation that provides an Slack C2 channel☆69Jan 5, 2026Updated 6 months ago
- A C# tool for requesting certificates from ADCS using DCOM over SMB. This tool allows you to remotely request X.509 certificates from CA …☆168Nov 2, 2025Updated 8 months ago
- Rust rewrite of nanodump, a low-level LSASS memory dumping tool.☆16Feb 22, 2026Updated 4 months ago
- Library that provides Python examples for interacting with the Cobalt Strike REST API☆25Nov 26, 2025Updated 7 months ago
- BingusLdr is a DLL loader built with Crystal Palace that uses a CET compatible stack spoofing technique.☆89Updated this week
- Repo hacks☆21Dec 7, 2025Updated 7 months ago