bestspear / ReBeacon_ForClang
Beacon compiled using clang
☆58Updated last year
Related projects: ⓘ
- more conveniently Visual-Studio-BOF-template☆45Updated last year
- An implementation of an indirect system call☆99Updated last year
- ☆38Updated 11 months ago
- Load shellcode via syscall☆47Updated 3 years ago
- vehsyscall:a syscall project that may bypass EDR☆41Updated 6 months ago
- shellcode生成框架☆75Updated 2 months ago
- power-kill is a project that kill protected processes (such as EDR or AV) by injecting shellcode into high privilege processes☆46Updated 2 years ago
- ☆85Updated 3 years ago
- ReturnGate, just like HellsGate.☆65Updated 2 years ago
- Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from mem…☆28Updated 4 months ago
- ☆26Updated last year
- Self Cleanup in post-ex job☆38Updated last week
- TeamServer and Client of Exploration Command and Control Framework☆31Updated this week
- ☆41Updated 5 months ago
- It stinks☆99Updated 2 years ago
- ☆31Updated 4 years ago
- kill AV/EDR☆20Updated last year
- ☆46Updated 3 years ago
- Golang implementation of Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll;☆31Updated 2 years ago
- Amaterasu terminates, or inhibits, protected processes such as application control and AV/EDR solutions by leveraging the Sysinternals Pr…☆67Updated 6 months ago
- CobaltStrike4.5 Sleeve解密文件,搬砖加一点点修改, 仅作备份使用.☆29Updated 2 years ago
- Just another version of the custom stack call from Proxy-Function-Calls-For-ETwTI☆31Updated last year
- use aswArPot.sys to kill process☆64Updated 2 years ago
- CLIPBRDWNDCLASS process injection technique(BOF) - execute beacon shellcode in callback☆63Updated 2 years ago
- Beacon Object File implementation of pwn1sher's KillDefender☆55Updated 2 years ago
- Evasive loader to bypass static detection☆50Updated 8 months ago
- Silently Install Chrome Extension For Persistence☆40Updated 2 months ago
- Shellcode Reductio Entropy Tools☆61Updated 11 months ago
- 自定义函数堆栈,从而绕过ETW检测,这个是完整版。☆10Updated 5 months ago
- Use COM Component Bypass UAC,Dll Version☆30Updated 3 years ago