Deep insights into EDR detection approaches
☆75Aug 23, 2026Updated last week
Alternatives and similar repositories for EDR-Introspection
Users that are interested in EDR-Introspection are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- some research on EDR deconditioning☆15Jun 4, 2026Updated 2 months ago
- This repository contains the research tool presented at x33fcon 2026, along with the associated presentation slides. The content is made …☆65Jun 15, 2026Updated 2 months ago
- Detonate redteam tools on VMs and get logs & detection status☆106Aug 14, 2026Updated 2 weeks ago
- Orchestrate detonating redteam artifacts in VMs with different EDRs to see their detection surface.☆79Aug 14, 2026Updated 2 weeks ago
- Shellcode capable of bypassing EAF / IAF mitigations☆30Apr 11, 2023Updated 3 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- open source port/reimplementation of the Cobalt Strike BOF Loader as is☆74Mar 8, 2026Updated 5 months ago
- List of awesome MalDev, Offensive Security, Hacking links☆88Updated this week
- Malleable Caddy Redirector☆20Apr 24, 2026Updated 4 months ago
- A Windows rootkit that turns user-land processes into Protected Processes☆30Nov 16, 2024Updated last year
- Cobalt Strike BOF☆60Dec 10, 2025Updated 8 months ago
- Collect Windows telemetry for Maldev☆504Aug 14, 2026Updated 2 weeks ago
- Generate DLL proxy/sideload projects. Automatically parses PE export tables and generates ready-to-compile project for red team engagemen…☆157Mar 8, 2026Updated 5 months ago
- Dynamically resolve API function addresses at runtime in a secure manner.☆74Nov 11, 2025Updated 9 months ago
- demo unhooking functions in ntdll☆28Jul 15, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- dcsync bof☆54Feb 13, 2026Updated 6 months ago
- Show the time in Roman Numerals☆12Jan 23, 2020Updated 6 years ago
- A proof of concept AMSI & ETW bypass using trampolines for hooking and modifying execution flow☆19Jun 26, 2025Updated last year
- A basic Terraform configuration for provisioning simple red team infrastructure in DigitalOcean☆12May 5, 2021Updated 5 years ago
- A truly Position Independent Code (PIC) NimPlant C2 beacon written in C, without reflective loading.☆67Feb 11, 2025Updated last year
- Linker for Beacon Object Files☆191Aug 14, 2026Updated 2 weeks ago
- Ported from [LACUNA Chain](https://github.com/MazX0p/LACUNA-Chain) by Mohamed Alzhrani (0xmaz). lacuna-rs is a reusable Rust crate that …☆18Jul 2, 2026Updated last month
- psexec-like remote execution using the paexec wire protocol that supports paexec and remoteexecm2 from manageengine adselfservice plus☆43Mar 24, 2026Updated 5 months ago
- Proof-of-Concept exploit for CVE-2026-32223☆21Apr 17, 2026Updated 4 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Arsenal of modules to beacon postex☆107Mar 13, 2026Updated 5 months ago
- Pointer encryption library in rust.☆16Apr 13, 2025Updated last year
- Evasive loader for .NET Framework assemblies☆52May 14, 2026Updated 3 months ago
- Locate dlls and function addresses without PEB Walk and EAT parsing☆110Nov 7, 2025Updated 9 months ago
- Clean Indirect Syscalls with Hook Evasion & Return Address Spoofing.☆102Apr 30, 2026Updated 4 months ago
- One WSL BOF to rule them all☆190Jan 14, 2026Updated 7 months ago
- A compiled language for Windows position-independent x86-64 shellcode and Beacon Object Files.☆181Jun 28, 2026Updated 2 months ago
- A Proof of Concept demonstrating CET-compliant callstack spoofing in Rust. It leverages Windows Thread Pool and Enum Callback trampolinin…☆59Jul 12, 2026Updated last month
- ☆215Jun 11, 2026Updated 2 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Windows native ETW inspection suite for browsing providers, reading metadata, consuming live events, recording ETL traces, filtering resu…☆111Jul 27, 2026Updated last month
- ☆64Jul 12, 2026Updated last month
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆279Apr 16, 2026Updated 4 months ago
- Overview of MS Defender☆156Feb 20, 2026Updated 6 months ago
- Print the stack trace☆51Mar 8, 2026Updated 5 months ago
- Kernel Process Termination Tool ( CVE-2026-0828 exploit)☆38Apr 2, 2026Updated 4 months ago
- Aggressor script that gets the latest commands from CobaltStrikes web site and creates an aggressor script based on tool options.☆23Oct 6, 2021Updated 4 years ago