Deep insights into EDR detection approaches
☆24Jul 7, 2026Updated last week
Alternatives and similar repositories for EDR-Introspection
Users that are interested in EDR-Introspection are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- some research on EDR deconditioning☆15Jun 4, 2026Updated last month
- This repository contains the research tool presented at x33fcon 2026, along with the associated presentation slides. The content is made …☆62Jun 15, 2026Updated last month
- Detonate redteam tools on VMs and get logs & detection status☆97Jun 22, 2026Updated 3 weeks ago
- Orchestrate detonating redteam artifacts in VMs with different EDRs to see their detection surface.☆63Jun 24, 2026Updated 3 weeks ago
- Shellcode capable of bypassing EAF / IAF mitigations☆30Apr 11, 2023Updated 3 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- open source port/reimplementation of the Cobalt Strike BOF Loader as is☆73Mar 8, 2026Updated 4 months ago
- Awesome MalDev Links☆77Jun 21, 2026Updated 3 weeks ago
- Malleable Caddy Redirector☆17Apr 24, 2026Updated 2 months ago
- A Windows rootkit that turns user-land processes into Protected Processes☆30Nov 16, 2024Updated last year
- Cobalt Strike BOF☆58Dec 10, 2025Updated 7 months ago
- demo unhooking functions in ntdll☆28Jul 15, 2025Updated last year
- Pointer encryption library in rust.☆16Apr 13, 2025Updated last year
- dcsync bof☆54Feb 13, 2026Updated 5 months ago
- Bypassing AVs and Sandboxes☆21Oct 9, 2025Updated 9 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Simple script to bypass AMSI on Win 10 and Win 11 by exploiting AmsiOpenSession☆16Jan 2, 2026Updated 6 months ago
- Show the time in Roman Numerals☆12Jan 23, 2020Updated 6 years ago
- A proof of concept AMSI & ETW bypass using trampolines for hooking and modifying execution flow☆19Jun 26, 2025Updated last year
- A basic Terraform configuration for provisioning simple red team infrastructure in DigitalOcean☆12May 5, 2021Updated 5 years ago
- Linker for Beacon Object Files☆191Jun 27, 2026Updated 3 weeks ago
- Ported from [LACUNA Chain](https://github.com/MazX0p/LACUNA-Chain) by Mohamed Alzhrani (0xmaz). lacuna-rs is a reusable Rust crate that …☆18Jul 2, 2026Updated 2 weeks ago
- psexec-like remote execution using the paexec wire protocol that supports paexec and remoteexecm2 from manageengine adselfservice plus☆43Mar 24, 2026Updated 3 months ago
- Proof-of-Concept exploit for CVE-2026-32223☆21Apr 17, 2026Updated 3 months ago
- Evasive loader for .NET Framework assemblies☆44May 14, 2026Updated 2 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Arsenal of modules to beacon postex☆105Mar 13, 2026Updated 4 months ago
- Locate dlls and function addresses without PEB Walk and EAT parsing☆110Nov 7, 2025Updated 8 months ago
- Clean Indirect Syscalls with Hook Evasion & Return Address Spoofing.☆98Apr 30, 2026Updated 2 months ago
- One WSL BOF to rule them all☆178Jan 14, 2026Updated 6 months ago
- A compiled language for Windows position-independent x86-64 shellcode and Beacon Object Files.☆175Jun 28, 2026Updated 3 weeks ago
- Using LNK files and user input simulation to start processes under explorer.exe☆34Sep 21, 2024Updated last year
- Windows native ETW inspection suite for browsing providers, reading metadata, consuming live events, recording ETL traces, filtering resu…☆89Jun 27, 2026Updated 3 weeks ago
- ☆199Jun 11, 2026Updated last month
- ☆51Jul 12, 2026Updated last week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A Proof of Concept demonstrating CET-compliant callstack spoofing in Rust. It leverages Windows Thread Pool and Enum Callback trampolinin…☆45Jul 12, 2026Updated last week
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆273Apr 16, 2026Updated 3 months ago
- Overview of MS Defender☆155Feb 20, 2026Updated 5 months ago
- Kernel Process Termination Tool ( CVE-2026-0828 exploit)☆37Apr 2, 2026Updated 3 months ago
- Print the stack trace☆51Mar 8, 2026Updated 4 months ago
- Aggressor script that gets the latest commands from CobaltStrikes web site and creates an aggressor script based on tool options.☆23Oct 6, 2021Updated 4 years ago
- EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies☆44Jun 8, 2026Updated last month