dosxuz / DefenderStopLinks
Stop Defender Service using C# via Token Impersonation
☆171Updated 3 years ago
Alternatives and similar repositories for DefenderStop
Users that are interested in DefenderStop are comparing it to the libraries listed below
Sorting:
- Shellcode launcher for AV bypass☆215Updated last year
- PowerShell Constrained Language Mode Bypass☆270Updated 4 years ago
- This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR …☆256Updated 2 years ago
- C# Lsass parser☆295Updated 3 years ago
- ☆391Updated 4 years ago
- A User Impersonation tool - via Token or Shellcode injection☆416Updated 3 years ago
- An other No-Fix LPE, NTLMRelay2Self over HTTP (Webdav).☆406Updated last year
- Koppeling x Metatwin x LazySign☆213Updated 3 years ago
- A collection of code snippets built to assist with breaking chains.☆117Updated last year
- Python library with CLI allowing to remotely dump domain user credentials via an ADCS without dumping the LSASS process memory☆392Updated last year
- Bypass AMSI by patching AmsiScanBuffer☆267Updated 4 years ago
- Generate BloodHound compatible JSON from logs written by ldapsearch BOF, pyldapsearch and Brute Ratel's LDAP Sentinel☆342Updated last year
- Collection of remote authentication triggers in C#☆492Updated last year
- Recovering NTLM hashes from Credential Guard☆339Updated 2 years ago
- Identifies the bytes that Microsoft Defender flags on.☆88Updated 3 years ago
- ☆164Updated 2 years ago
- A new AMSI Bypass technique using .NET ALI Call Hooking.☆191Updated 2 years ago
- This POC gives you the possibility to compile a .exe to completely avoid statically detection by AV/EPP/EDR of your C2-shellcode and down…☆247Updated 2 years ago
- OPSEC safe Kerberoasting in C#☆192Updated 3 years ago
- COM Hijacking VOODOO☆299Updated 3 months ago
- Module Stomping, No New Thread, HellsGate syscaller, UUID Shellcode Runner for x64 Windows 10!☆445Updated 2 years ago
- LiquidSnake is a tool that allows operators to perform fileless lateral movement using WMI Event Subscriptions and GadgetToJScript☆338Updated 3 years ago
- Windows Local Privilege Escalation via CdpSvc service (Writeable SYSTEM path Dll Hijacking)☆254Updated 2 years ago
- Creating a repository with all public Beacon Object Files (BoFs)☆506Updated last year
- Python implementation for PetitPotam☆202Updated 3 years ago
- BadAssMacros - C# based automated Malicous Macro Generator.☆424Updated 3 years ago
- Hookers are cooler than patches.☆169Updated 3 years ago
- Collection of some of my own tools with other great open source tools out there packaged into a powershell module☆145Updated 2 years ago
- ☆409Updated last year
- official repo for the AdHuntTool (part of the old RedTeamCSharpScripts repo)☆233Updated 3 years ago