γπγProof of concept on BYOVD attack
β165Dec 7, 2024Updated last year
Alternatives and similar repositories for Reaper
Users that are interested in Reaper are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- β60Dec 15, 2023Updated 2 years ago
- C# AV/EDR Killer using less-known driver (BYOVD)β188Nov 10, 2023Updated 2 years ago
- Terminate AV/EDR leveraging BYOVD attackβ106Mar 21, 2025Updated last year
- Abusing Windows fork API and OneDrive.exe process to inject the malicious shellcode without allocating new RWX memory region.β292May 27, 2024Updated 2 years ago
- Terminate AV/EDR Processes using kernel driverβ354Jun 12, 2023Updated 3 years ago
- GPUs on demand by Runpod - Special Offer Available β’ AdRun AI, ML, and HPC workloads on powerful cloud GPUsβwithout limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- An interactive shell to spoof some LOLBins command lineβ188Jan 27, 2024Updated 2 years ago
- A variation of ProcessOverwriting to execute shellcode on an executable's sectionβ147Dec 16, 2023Updated 2 years ago
- Abusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes.β411Mar 16, 2026Updated 4 months ago
- CIA UAC bypass implementation of Stinger that obtains the token from an auto-elevated process, modifies it, and reuses it to execute as Aβ¦β300Feb 2, 2026Updated 6 months ago
- γβοΈγDetect which native Windows API's (NtAPI) are being hookedβ40Dec 7, 2024Updated last year
- yet another AV killer tool using BYOVDβ313Dec 12, 2023Updated 2 years ago
- Modify managed functions from unmanaged codeβ53Feb 1, 2024Updated 2 years ago
- β123Oct 9, 2023Updated 2 years ago
- Lateral Movement via the .NET Profilerβ101Nov 21, 2024Updated last year
- Managed hosting for WordPress and PHP on Cloudways β’ AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Kill AV/EDR leveraging BYOVD attackβ406Jul 11, 2023Updated 3 years ago
- Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.β326Apr 12, 2024Updated 2 years ago
- Basic interactive Windows kernel offensive toolkit written in Cβ137Sep 20, 2025Updated 10 months ago
- β70Oct 30, 2023Updated 2 years ago
- Work, timer, and wait callback example using solely Native Windows APIs.β89Feb 11, 2024Updated 2 years ago
- Source generator to add D/Invoke and indirect syscall methods to a C# project.β193Mar 4, 2024Updated 2 years ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it uselessβ40Jul 12, 2024Updated 2 years ago
- γπ§±γTest a list of payloads and see if you can bypass itβ64Jun 4, 2022Updated 4 years ago
- An App Domain Manager Injection DLL PoC on steroidsβ216Dec 14, 2023Updated 2 years ago
- AI Agents on DigitalOcean Gradient AI Platform β’ AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Bypass the Event Trace Windows(ETW) and unhook ntdll.β116Sep 29, 2023Updated 2 years ago
- Exploitation of echo_driver.sysβ170Sep 16, 2023Updated 2 years ago
- Deobfuscation of XorStringsNetβ13Nov 5, 2024Updated last year
- Reproducing Spyboy technique to terminate all EDR/XDR/AVs processesβ1,061Jun 20, 2023Updated 3 years ago
- Automated DLL Sideloading Tool With EDR Evasion Capabilitiesβ507Dec 19, 2023Updated 2 years ago
- Remote Shellcode Injectorβ220Aug 27, 2023Updated 2 years ago
- kill anti-malware protected processes ( BYOVD )β984Jul 21, 2023Updated 3 years ago
- A memory-based evasion technique which makes shellcode invisible from process start to end.β1,200Oct 16, 2023Updated 2 years ago
- RDPCredentialStealer it's an implant that steal credentials provided by users in RDP using API Hooking with Detours in C++β266Mar 11, 2026Updated 5 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer β’ AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A sophisticated, covert Windows-based credential dumper using C++ and MASM x64.β441Jul 8, 2024Updated 2 years ago
- .net config loaderβ356Nov 9, 2023Updated 2 years ago
- RunPE implementation with multiple evasive techniques (1)β390Sep 22, 2023Updated 2 years ago
- Analyse your malware to surgically obfuscate itβ545Jun 27, 2026Updated last month
- C++ self-Injecting dropper based on various EDR evasion techniques.β442Feb 11, 2024Updated 2 years ago
- Execute shellcode files with rundll32β224Jan 28, 2024Updated 2 years ago
- Extracting NetNTLM without touching lsass.exeβ245Nov 27, 2023Updated 2 years ago