bluedragonsecurity / bds_userlandLinks
Linux userland rootkit. Hides file and directory, hides process, hides bind shell port, hides daemon port, hides reverse shell port, cleans up bash history and logs during installation
☆17Updated 2 years ago
Alternatives and similar repositories for bds_userland
Users that are interested in bds_userland are comparing it to the libraries listed below
Sorting:
- about how to make a anti-virus engine☆94Updated 6 months ago
- A Blind EDR Project for Educational Purposes☆90Updated 10 months ago
- Hide processes, files, services in Windows ring3☆30Updated last year
- shellcode生成框架☆87Updated last year
- A method to execute syscalls while bypassing EDR's function hooking and call stack analysis.☆24Updated 7 months ago
- Shellcode obfuscation tool to avoid AV/EDR.☆131Updated 2 years ago
- shellcode-loaders and beacon-loaders☆71Updated 2 years ago
- C2☆116Updated 3 weeks ago
- 复现《EDR的梦魇:Storm-0978使用新型内核注入技术“Step Bear”》☆141Updated last year
- Load static-compiled PE from remote server.☆68Updated 3 years ago
- ☆100Updated 2 years ago
- Exploit for CVE-2023-29360 targeting MSKSSRV.SYS driver☆150Updated 2 years ago
- The tool used to clone the digital signatures of legitimate programs☆42Updated last month
- 基于Tinynuke修复得到的HVNC☆185Updated 4 years ago
- Loading Fileless Remote PE from URI to memory with argument passing and ETW patching and NTDLL unhooking and No New Thread technique☆74Updated 3 years ago
- Windows LPE☆136Updated last year
- An implementation of an indirect system call☆131Updated 2 years ago
- A C implementation for a stealth injection method☆36Updated 3 weeks ago
- Open repository for learning dynamic shellcode loading (sample in many programming languages)☆269Updated 4 months ago
- ☆30Updated 4 months ago
- ☆25Updated 6 months ago
- ProcessGhosting 技术的 rust 实现版本☆25Updated last year
- ShadeLoader is a shellcode loader designed to bypass most antivirus software. 壳代码, 杀毒软件, 绕过☆41Updated 6 months ago
- UAC Bypass using UIAccess program QuickAssist☆138Updated last week
- Create a new thread that will suspend every thread and encrypt its stack, then going to sleep , then decrypt the stacks and resume thread…☆164Updated 2 years ago
- ☆33Updated 2 years ago
- ☆141Updated 8 months ago
- Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR …☆287Updated last year
- Converts exe to shellcode.☆117Updated last year
- PoC for thread pool based process injection in Windows.☆118Updated 8 months ago