γπγProof of concept on BYOVD attack
β166Dec 7, 2024Updated last year
Alternatives and similar repositories for Reaper
Users that are interested in Reaper are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- β60Dec 15, 2023Updated 2 years ago
- C# AV/EDR Killer using less-known driver (BYOVD)β188Nov 10, 2023Updated 2 years ago
- Terminate AV/EDR leveraging BYOVD attackβ104Mar 21, 2025Updated last year
- Abusing Windows fork API and OneDrive.exe process to inject the malicious shellcode without allocating new RWX memory region.β293May 27, 2024Updated 2 years ago
- Terminate AV/EDR Processes using kernel driverβ352Jun 12, 2023Updated 3 years ago
- Proton VPN Special Offer - Get 70% off β’ AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- An interactive shell to spoof some LOLBins command lineβ188Jan 27, 2024Updated 2 years ago
- A variation of ProcessOverwriting to execute shellcode on an executable's sectionβ147Dec 16, 2023Updated 2 years ago
- Abusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes.β410Mar 16, 2026Updated 6 months ago
- CIA UAC bypass implementation of Stinger that obtains the token from an auto-elevated process, modifies it, and reuses it to execute as Aβ¦β300Feb 2, 2026Updated 7 months ago
- γβοΈγDetect which native Windows API's (NtAPI) are being hookedβ40Dec 7, 2024Updated last year
- yet another AV killer tool using BYOVDβ314Dec 12, 2023Updated 2 years ago
- Modify managed functions from unmanaged codeβ53Feb 1, 2024Updated 2 years ago
- β122Oct 9, 2023Updated 2 years ago
- Lateral Movement via the .NET Profilerβ101Nov 21, 2024Updated last year
- Deploy open-source AI quickly and easily - Special Bonus Offer β’ AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Kill AV/EDR leveraging BYOVD attackβ406Jul 11, 2023Updated 3 years ago
- Basic interactive Windows kernel offensive toolkit written in Cβ138Sep 20, 2025Updated last year
- Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.β325Apr 12, 2024Updated 2 years ago
- β70Oct 30, 2023Updated 2 years ago
- Work, timer, and wait callback example using solely Native Windows APIs.β88Feb 11, 2024Updated 2 years ago
- Source generator to add D/Invoke and indirect syscall methods to a C# project.β192Mar 4, 2024Updated 2 years ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it uselessβ40Jul 12, 2024Updated 2 years ago
- γπ§±γTest a list of payloads and see if you can bypass itβ64Jun 4, 2022Updated 4 years ago
- kill anti-malware protected processes ( BYOVD )β990Jul 21, 2023Updated 3 years ago
- Managed Kubernetes at scale on DigitalOcean β’ AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Bypass the Event Trace Windows(ETW) and unhook ntdll.β116Sep 29, 2023Updated 2 years ago
- Exploitation of echo_driver.sysβ168Sep 16, 2023Updated 3 years ago
- Deobfuscation of XorStringsNetβ13Nov 5, 2024Updated last year
- An App Domain Manager Injection DLL PoC on steroidsβ238Dec 14, 2023Updated 2 years ago
- Reproducing Spyboy technique to terminate all EDR/XDR/AVs processesβ1,061Jun 20, 2023Updated 3 years ago
- Automated DLL Sideloading Tool With EDR Evasion Capabilitiesβ507Dec 19, 2023Updated 2 years ago
- Remote Shellcode Injectorβ220Aug 27, 2023Updated 3 years ago
- A memory-based evasion technique which makes shellcode invisible from process start to end.β1,199Oct 16, 2023Updated 2 years ago
- RDPCredentialStealer it's an implant that steal credentials provided by users in RDP using API Hooking with Detours in C++β280Mar 11, 2026Updated 6 months ago
- Deploy on Railway without the complexity - Free Credits Offer β’ AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- .net config loaderβ355Nov 9, 2023Updated 2 years ago
- RunPE implementation with multiple evasive techniques (1)β388Sep 22, 2023Updated 2 years ago
- Analyse your malware to surgically obfuscate itβ546Jun 27, 2026Updated 2 months ago
- C++ self-Injecting dropper based on various EDR evasion techniques.β444Feb 11, 2024Updated 2 years ago
- Execute shellcode files with rundll32β227Jan 28, 2024Updated 2 years ago
- Extracting NetNTLM without touching lsass.exeβ245Nov 27, 2023Updated 2 years ago
- Two new offensive techniques using Windows Fibers: PoisonFiber (The first remote enumeration & Fiber injection capability POC tool) Phanβ¦β285Sep 18, 2024Updated 2 years ago