backdoorskid / ClrAmsiScanPatcherLinks
Patches the AmsiScan function in clr.dll allowing for unrestricted assembly loading in .NET
☆37Updated 2 months ago
Alternatives and similar repositories for ClrAmsiScanPatcher
Users that are interested in ClrAmsiScanPatcher are comparing it to the libraries listed below
Sorting:
- Repository to gather the .NET malware I will be developing☆18Updated 3 months ago
- early cascade injection PoC based on Outflanks blog post, in rust☆60Updated 8 months ago
- An Aggressor Script that utilizes NtCreateUserProcess to run binaries☆30Updated 5 months ago
- converts sRDI compatible dlls to shellcode☆29Updated 5 months ago
- PoC to self-delete a binary in C#☆33Updated last year
- Shellcode Loader Utilizing ETW Events☆63Updated 4 months ago
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆75Updated 11 months ago
- Section-based payload obfuscation technique for x64☆64Updated 11 months ago
- Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials☆53Updated 2 months ago
- C# API for Nidhogg rootkit☆17Updated last year
- Locate dlls and function addresses without PEB Walk and EAT parsing☆35Updated this week
- Simple C# Redirector☆88Updated 7 months ago
- BOF for C2 framework☆41Updated 8 months ago
- Proxy function calls through the thread pool with ease☆28Updated 4 months ago
- "D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system c…☆24Updated 10 months ago
- Bypassing Amsi using LdrLoadDll☆45Updated 6 months ago
- A C# implementation of dumping credentials from Windows Credential Manager☆59Updated last year
- ☆66Updated 5 months ago
- Windows NTLM hash dump utility written in C language, that supports Windows and Linux. Hashes can be dumped in realtime or from already s…☆63Updated last year
- Playing with packets in C#☆14Updated 11 months ago
- ☆86Updated 10 months ago
- Modify managed functions from unmanaged code☆52Updated last year
- A BOF that suspends non-GUI threads for a target process or resumes them resulting in stealthy process silencing.☆53Updated 3 months ago
- ☆42Updated 3 weeks ago
- ☆55Updated 8 months ago
- a demo module for the kaine agent to execute and inject assembly modules☆39Updated 10 months ago
- Cortex EDR Ransomware protection Bypass☆24Updated 5 months ago
- ☆52Updated 6 months ago
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆50Updated last year
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆78Updated 11 months ago