bluedragonsecurity / bds_userlandLinks
Linux userland rootkit. Hides file and directory, hides process, hides bind shell port, hides daemon port, hides reverse shell port, cleans up bash history and logs during installation
☆17Updated 2 years ago
Alternatives and similar repositories for bds_userland
Users that are interested in bds_userland are comparing it to the libraries listed below
Sorting:
- A method to execute syscalls while bypassing EDR's function hooking and call stack analysis.☆23Updated 6 months ago
- about how to make a anti-virus engine☆91Updated 5 months ago
- Shellcode obfuscation tool to avoid AV/EDR.☆130Updated 2 years ago
- ☆100Updated 2 years ago
- shellcode生成框架☆87Updated last year
- Open repository for learning dynamic shellcode loading (sample in many programming languages)☆268Updated 3 months ago
- Exploit for CVE-2023-29360 targeting MSKSSRV.SYS driver☆151Updated 2 years ago
- Load static-compiled PE from remote server.☆67Updated 3 years ago
- C2☆115Updated 3 weeks ago
- An implementation of an indirect system call☆131Updated 2 years ago
- Hide processes, files, services in Windows ring3☆30Updated last year
- 复现《EDR的梦魇:Storm-0978使用新型内核注入技术“Step Bear”》☆140Updated last year
- Loading Fileless Remote PE from URI to memory with argument passing and ETW patching and NTDLL unhooking and No New Thread technique☆73Updated 3 years ago
- PoC for thread pool based process injection in Windows.☆117Updated 7 months ago
- Create a new thread that will suspend every thread and encrypt its stack, then going to sleep , then decrypt the stacks and resume thread…☆162Updated 2 years ago
- Windows LPE☆134Updated last year
- Converts exe to shellcode.☆116Updated last year
- ☆276Updated last year
- Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR …☆286Updated last year
- Windows PE Signature Thief in C++☆51Updated 5 years ago
- 基于Tinynuke修复得到的HVNC☆173Updated 4 years ago
- A WIP shellcode loader tool which bypasses AV/EDR, coded in C++, and equipped with a minimal builder.☆76Updated last month
- Windows LPE exploit for CVE-2022-37969☆136Updated 2 years ago
- UAC Bypass using UIAccess program QuickAssist☆128Updated 8 months ago
- A Blind EDR Project for Educational Purposes☆57Updated 9 months ago
- Simulate per-process disconnection in red team environments☆111Updated 5 months ago
- Client/server code that impersonates TLS 1.3 to disguise C2 activity.☆73Updated 3 years ago
- shellcode-loaders and beacon-loaders☆70Updated 2 years ago
- ☆33Updated 2 years ago
- Process injection alternative☆344Updated last year