amjcyber / EDRNoiseMakerLinks
Detect WFP filters blocking EDR communications
☆96Updated 2 years ago
Alternatives and similar repositories for EDRNoiseMaker
Users that are interested in EDRNoiseMaker are comparing it to the libraries listed below
Sorting:
- Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination…☆139Updated last year
- ☆159Updated last year
- Windows Persistence IT-Security☆109Updated 10 months ago
- This repo will contain the core detection, only for Cobaltstrike's leaked versions. Non-leaked version detections wont be shared☆89Updated 2 years ago
- Lateral Movement☆125Updated 2 years ago
- A lightweight Windows Prefetch file parser to extract programs' execution history☆42Updated last week
- BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR☆75Updated last year
- Two in one, patch lifetime powershell console, no more etw and amsi!☆101Updated 8 months ago
- A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.☆256Updated 3 months ago
- PoC for using MS Windows printers for persistence / command and control via Internet Printing☆149Updated last year
- Decrypt GlobalProtect configuration and cookie files.☆158Updated last year
- WTSImpersonator utilizes WTSQueryUserToken to steal user tokens by abusing the RPC Named Pipe "\\pipe\LSM_API_service"☆122Updated last year
- sideloading PoC using onedrive.exe & version.dll☆88Updated 2 months ago
- Охотник (Hunter) is a simple Adversary Simulation tool developed for achieves stealth through API unhooking, direct and indirect syscalls…☆90Updated 8 months ago
- Example code samples from our ScriptBlock Smuggling Blog post☆94Updated last year
- EDR-Redir : a tool used to redirect the EDR's folder to another location.☆221Updated 2 months ago
- A BOF to enumerate system process, their protection levels, and more.☆124Updated last year
- ☆119Updated last year
- Tool to extract username and password of current user from PanGPA in plaintext☆88Updated last year
- StoneKeeper C2, an experimental EDR evasion framework for research purposes☆207Updated last year
- AutoRMM is a collection of scripts and instructions we are organizing, to test delivery mechanisms for RMM and screen sharing tools, alo…☆91Updated 5 months ago
- BloodHound PowerShell client☆75Updated last month
- ☆160Updated 11 months ago
- POC of GITHUB simple C2 in rust☆52Updated 5 months ago
- An interactive shell to spoof some LOLBins command line☆187Updated last year
- C# implementation of TokenFinder. Steal M365 access tokens from Office Desktop apps☆144Updated last year
- Local & remote Windows DLL Proxying☆169Updated last year
- Interactive Shell and Command Execution over Named-Pipes (SMB) for Fileless lateral movement☆180Updated 8 months ago
- Utilizng an MCP Server to communicate with your C2☆85Updated 8 months ago
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆92Updated last year