arosenmund / defcon33_silence_kill_edrView external linksLinks
☆334Aug 20, 2025Updated 5 months ago
Alternatives and similar repositories for defcon33_silence_kill_edr
Users that are interested in defcon33_silence_kill_edr are comparing it to the libraries listed below
Sorting:
- ☆55May 31, 2025Updated 8 months ago
- Lateral movement with DCOM DLL hijacking☆177Jul 4, 2025Updated 7 months ago
- ☆53Sep 23, 2025Updated 4 months ago
- Alternative Read and Write primitives using Rtl* functions the unintended way.☆78Aug 25, 2025Updated 5 months ago
- Locate dlls and function addresses without PEB Walk and EAT parsing☆104Nov 7, 2025Updated 3 months ago
- Payload Generation Workflow☆40Jul 18, 2025Updated 6 months ago
- ForsHops☆152Mar 25, 2025Updated 10 months ago
- ☆85May 15, 2025Updated 9 months ago
- ☆31Aug 13, 2025Updated 6 months ago
- Nameless C2 - A C2 with all its components written in Rust☆282Sep 26, 2024Updated last year
- Stage 0☆169Dec 18, 2024Updated last year
- Huffman Coding in Shellcode Obfuscation & Dynamic Indirect Syscalls Loader.☆281Apr 6, 2025Updated 10 months ago
- Demonstration of Early Bird APC Injection - MITRE ID T1055.004☆35Oct 31, 2023Updated 2 years ago
- Linker for Beacon Object Files☆154Updated this week
- DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely☆381Dec 13, 2024Updated last year
- A Rust implementation of GodPotato — abusing SeImpersonate to gain SYSTEM privileges. Includes a TCP-based reverse shell and indirect NTA…☆355Apr 26, 2025Updated 9 months ago
- Run native PE or .NET executables entirely in-memory. Build the loader as an .exe or .dll—DllMain is Cobalt Strike UDRL-compatible☆269Jun 18, 2025Updated 7 months ago
- remote process injections using pool party techniques☆70Jun 29, 2025Updated 7 months ago
- gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory env…☆329Jan 14, 2026Updated last month
- ☆333Sep 21, 2025Updated 4 months ago
- Evasive Payload Delivery Server & C2 Redirector☆112Nov 3, 2025Updated 3 months ago
- This is the tool to dump the LSASS process on modern Windows 11☆555Nov 1, 2025Updated 3 months ago
- Local SYSTEM auth trigger for relaying☆168Jul 22, 2025Updated 6 months ago
- A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.☆408Jan 11, 2026Updated last month
- ☆198Mar 28, 2025Updated 10 months ago
- PoC exploit for the vulnerable WatchDog Anti-Malware driver (amsdk.sys) – weaponized to kill protected EDR/AV processes via BYOVD.☆180Sep 11, 2025Updated 5 months ago
- Hells Hollow Windows 11 Rootkit technique to Hook the SSDT via Alt Syscalls☆214Aug 31, 2025Updated 5 months ago
- EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.☆801Nov 1, 2025Updated 3 months ago
- Rust implementation, creating a scheduled task programmatically with user logon trigger.☆47Jun 10, 2025Updated 8 months ago
- Bypasses AMSI protection through remote memory patching and parsing technique.☆54May 12, 2025Updated 9 months ago
- .NET tool used to enrich RPC telemetry☆101Jan 24, 2026Updated 3 weeks ago
- The dragon in the dark. A red team post exploitation framework for testing security controls during red team assessments.☆449Feb 7, 2026Updated last week
- StoneKeeper C2, an experimental EDR evasion framework for research purposes☆208Dec 25, 2024Updated last year
- A BOF that runs unmanaged PEs inline☆678Oct 23, 2024Updated last year
- COM-based DLL Surrogate Injection☆143Dec 9, 2025Updated 2 months ago
- NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-bui…☆231Feb 12, 2025Updated last year
- A PoC for Early Cascade process injection technique.☆208Jan 30, 2025Updated last year
- Metamorphic cross-compilation of C++ & C-code to PIC, BOF & EXE.☆601Feb 2, 2026Updated 2 weeks ago
- A new technique that can be used to bypass memory scanners. This can be useful in hiding problematic code (such as reflective loaders imp…☆339Oct 7, 2024Updated last year