abusing Process Hacker driver to terminate other processes (BYOVD)
☆84May 23, 2023Updated 3 years ago
Alternatives and similar repositories for Overlord
Users that are interested in Overlord are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Bypass Malware Sandbox Evasion Ram check☆142Jan 3, 2023Updated 3 years ago
- kill anti-malware protected processes ( BYOVD )☆984Jul 21, 2023Updated 3 years ago
- Hook system calls on Windows by using Kaspersky's hypervisor☆17Dec 25, 2024Updated last year
- Kernel Mode Driver for Elevating Process Privileges☆130Mar 23, 2023Updated 3 years ago
- This code example allows you to create a malware.exe sample that can be run in the context of a system service, and could be used for loc…☆55May 8, 2023Updated 3 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes☆1,061Jun 20, 2023Updated 3 years ago
- Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime☆309Aug 2, 2023Updated 3 years ago
- APT38 Tactic PoC for Stealing 0days from security researchers☆334May 30, 2025Updated last year
- Bypass Malware Time Delays☆105Sep 23, 2022Updated 3 years ago
- Block any Process to open HANDLE to your process , only SYTEM is allowed to open handle to your process ,with that you can avoid remote m…☆171Apr 27, 2023Updated 3 years ago
- Coffee is a loader for ELF (Executable and Linkable Format) object files written in Rust. Coffee是一个用Rust语言编写的ELF object文件的加载器☆63Apr 29, 2024Updated 2 years ago
- Now You See Me, Now You Don't☆1,062May 22, 2026Updated 2 months ago
- Implementation of ITaskHandler in C++☆15Feb 11, 2023Updated 3 years ago
- Hide Port In Windows☆41Jul 14, 2026Updated 3 weeks ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A simple BOF (Beacon Object File) to search files in the system☆20Dec 2, 2023Updated 2 years ago
- simple user-mode Rootkit☆106Oct 24, 2022Updated 3 years ago
- A Dropper POC with a focus on aiding in EDR evasion, NTDLL Unhooking followed by loading ntdll in-memory, which is present as shellcode (…☆178Feb 10, 2023Updated 3 years ago
- PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.☆628Sep 26, 2023Updated 2 years ago
- ZwProcessHollowing is a x64 process hollowing project which uses direct systemcalls, dll unhooking and RC4 payload decryption☆96Mar 23, 2023Updated 3 years ago
- Lifetime AMSI bypass☆681Sep 26, 2023Updated 2 years ago
- Shellcode Loader Implementing Indirect Dynamic Syscall , API Hashing, Fileless Shellcode retrieving using Winsock2☆296Jul 15, 2023Updated 3 years ago
- Threadless Process Injection using remote function hooking.☆825Sep 4, 2024Updated last year
- Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird …☆805Jan 26, 2026Updated 6 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Simple x86 Trampoline Hook☆44Aug 3, 2022Updated 4 years ago
- dlopen() filelessly a shared object or even a program (and run it).☆59Aug 31, 2023Updated 2 years ago
- C or BOF file to extract WebKit master key to decrypt user cookie☆211Apr 29, 2024Updated 2 years ago
- use aswArPot.sys to kill process☆68Aug 26, 2022Updated 3 years ago
- Execute unmanaged Windows executables in CobaltStrike Beacons☆723Mar 4, 2023Updated 3 years ago
- Simple PoC to locate hooked functions by EDR in ntdll.dll☆46Jul 16, 2023Updated 3 years ago
- Set the process mitigation policy for loading only Microsoft Modules , and block any userland 3rd party modules☆41May 6, 2023Updated 3 years ago
- This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret …☆267Apr 29, 2023Updated 3 years ago
- Bypassing UAC with SSPI Datagram Contexts☆472Sep 24, 2023Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- EDR Detector that can find what kind of endpoint solution is being used according to drivers in the system.☆95Nov 5, 2021Updated 4 years ago
- SharpElevator is a C# implementation of Elevator for UAC bypass. This UAC bypass was originally discovered by James Forshaw and publishe…☆63Aug 31, 2022Updated 3 years ago
- ☆567Feb 22, 2024Updated 2 years ago
- different ntdll unhooking techniques : unhooking ntdll from disk, from KnownDlls, from suspended process, from remote server (fileless)☆203Aug 2, 2023Updated 3 years ago
- PE obfuscator with Evasion in mind☆212Apr 25, 2023Updated 3 years ago
- Small PoC of using a Microsoft signed executable as a lolbin.☆140Feb 27, 2023Updated 3 years ago
- A PoC implementation for dynamically masking call stacks with timers.☆315Feb 13, 2023Updated 3 years ago