γπγProof of concept on BYOVD attack
β165Dec 7, 2024Updated last year
Alternatives and similar repositories for Reaper
Users that are interested in Reaper are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- β60Dec 15, 2023Updated 2 years ago
- C# AV/EDR Killer using less-known driver (BYOVD)β186Nov 10, 2023Updated 2 years ago
- Terminate AV/EDR leveraging BYOVD attackβ105Mar 21, 2025Updated last year
- Abusing Windows fork API and OneDrive.exe process to inject the malicious shellcode without allocating new RWX memory region.β293May 27, 2024Updated 2 years ago
- Terminate AV/EDR Processes using kernel driverβ355Jun 12, 2023Updated 3 years ago
- Managed Database hosting by DigitalOcean β’ AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- An interactive shell to spoof some LOLBins command lineβ188Jan 27, 2024Updated 2 years ago
- A variation of ProcessOverwriting to execute shellcode on an executable's sectionβ147Dec 16, 2023Updated 2 years ago
- Abusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes.β410Mar 16, 2026Updated 4 months ago
- CIA UAC bypass implementation of Stinger that obtains the token from an auto-elevated process, modifies it, and reuses it to execute as Aβ¦β301Feb 2, 2026Updated 5 months ago
- γβοΈγDetect which native Windows API's (NtAPI) are being hookedβ40Dec 7, 2024Updated last year
- yet another AV killer tool using BYOVDβ313Dec 12, 2023Updated 2 years ago
- Modify managed functions from unmanaged codeβ53Feb 1, 2024Updated 2 years ago
- β124Oct 9, 2023Updated 2 years ago
- Lateral Movement via the .NET Profilerβ100Nov 21, 2024Updated last year
- Serverless GPU API endpoints on Runpod - Get Bonus Credits β’ AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Kill AV/EDR leveraging BYOVD attackβ407Jul 11, 2023Updated 3 years ago
- Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.β326Apr 12, 2024Updated 2 years ago
- Basic interactive Windows kernel offensive toolkit written in Cβ138Sep 20, 2025Updated 10 months ago
- β70Oct 30, 2023Updated 2 years ago
- Work, timer, and wait callback example using solely Native Windows APIs.β89Feb 11, 2024Updated 2 years ago
- Source generator to add D/Invoke and indirect syscall methods to a C# project.β195Mar 4, 2024Updated 2 years ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it uselessβ40Jul 12, 2024Updated 2 years ago
- γπ§±γTest a list of payloads and see if you can bypass itβ64Jun 4, 2022Updated 4 years ago
- An App Domain Manager Injection DLL PoC on steroidsβ215Dec 14, 2023Updated 2 years ago
- Virtual machines for every use case on DigitalOcean β’ AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Bypass the Event Trace Windows(ETW) and unhook ntdll.β116Sep 29, 2023Updated 2 years ago
- Exploitation of echo_driver.sysβ170Sep 16, 2023Updated 2 years ago
- Deobfuscation of XorStringsNetβ13Nov 5, 2024Updated last year
- Reproducing Spyboy technique to terminate all EDR/XDR/AVs processesβ1,062Jun 20, 2023Updated 3 years ago
- Automated DLL Sideloading Tool With EDR Evasion Capabilitiesβ507Dec 19, 2023Updated 2 years ago
- Remote Shellcode Injectorβ220Aug 27, 2023Updated 2 years ago
- kill anti-malware protected processes ( BYOVD )β983Jul 21, 2023Updated 3 years ago
- A memory-based evasion technique which makes shellcode invisible from process start to end.β1,201Oct 16, 2023Updated 2 years ago
- RDPCredentialStealer it's an implant that steal credentials provided by users in RDP using API Hooking with Detours in C++β266Mar 11, 2026Updated 4 months ago
- Deploy on Railway without the complexity - Free Credits Offer β’ AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A sophisticated, covert Windows-based credential dumper using C++ and MASM x64.β441Jul 8, 2024Updated 2 years ago
- .net config loaderβ355Nov 9, 2023Updated 2 years ago
- RunPE implementation with multiple evasive techniques (1)β390Sep 22, 2023Updated 2 years ago
- Analyse your malware to surgically obfuscate itβ540Jun 27, 2026Updated 3 weeks ago
- C++ self-Injecting dropper based on various EDR evasion techniques.β442Feb 11, 2024Updated 2 years ago
- Execute shellcode files with rundll32β223Jan 28, 2024Updated 2 years ago
- Extracting NetNTLM without touching lsass.exeβ246Nov 27, 2023Updated 2 years ago