efchatz / bypassing-av-detection
Bypassing antivirus detection: old-school malware, new tricks
☆61Updated 2 years ago
Alternatives and similar repositories for bypassing-av-detection
Users that are interested in bypassing-av-detection are comparing it to the libraries listed below
Sorting:
- PE obfuscator with Evasion in mind☆212Updated 2 years ago
- A Dropper POC with a focus on aiding in EDR evasion, NTDLL Unhooking followed by loading ntdll in-memory, which is present as shellcode (…☆170Updated 2 years ago
- Evasive Golang Loader☆131Updated 9 months ago
- Create Anti-Copy DRM Malware☆56Updated 8 months ago
- Bypass Malware Sandbox Evasion Ram check☆137Updated 2 years ago
- Windows Kernel Offensive Toolset☆122Updated 8 months ago
- ApexLdr is a DLL Payload Loader written in C☆109Updated 10 months ago
- Execute shellcode from a remote-hosted bin file using Winhttp.☆234Updated last year
- NativePayload_PE1/PE2 , Injecting Meterpreter Payload bytes into local Process via Delegation Technique + in-memory with delay Changing R…☆58Updated last year
- 「💀」Proof of concept on BYOVD attack☆159Updated 5 months ago
- ☆248Updated 2 years ago
- A proof of concept for abusing exception handlers to hook and bypass user mode EDR hooks.☆187Updated last year
- ☆123Updated last year
- Shaco is a linux agent for havoc☆160Updated last year
- AV bypass while you sip your Chai!☆221Updated last year
- Do some DLL SideLoading magic☆83Updated last year
- Start with shellcode execution using Windows APIs (high level), move on to native APIs (medium level) and finally to direct syscalls (low…☆133Updated 2 years ago
- Shellcode loader designed for evasion. Coded in Rust.☆128Updated 2 years ago
- A Flask-based HTTP(S) command and control (C2) framework with a web interface. Custom Windows EXE/DLL implants written in C++. For educat…☆90Updated last year
- Run Your Payload Without Running Your Payload☆181Updated 2 years ago
- This project is an implant framework designed for long term persistent access to Windows machines.☆110Updated last year
- random code snippets, useful for getting started☆120Updated 6 months ago
- WIP shellcode loader in nim with EDR evasion techniques☆216Updated 3 years ago
- Kernel Mode Driver for Elevating Process Privileges☆133Updated 2 years ago
- .NET assembly loader with patchless AMSI and ETW bypass☆330Updated 2 years ago
- CaveCarver - PE backdooring tool which utilizes and automates code cave technique☆225Updated 2 years ago
- Improved version of EKKO by @5pider that Encrypts only Image Sections☆119Updated 2 years ago
- Patching AmsiOpenSession by forcing an error branching☆145Updated last year
- A variation of ProcessOverwriting to execute shellcode on an executable's section☆148Updated last year
- Some Rust program I wrote while learning Malware Development☆132Updated 3 months ago