about how to make a anti-virus engine
☆115May 22, 2025Updated last year
Alternatives and similar repositories for awesome_anti_virus_engine
Users that are interested in awesome_anti_virus_engine are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- 复现《EDR的梦魇:Storm-0978使用新型内核注入技术“Step Bear”》☆163Oct 27, 2024Updated last year
- Stack integrity verification to Detect SleepMask or CallStack Spoofer☆55Jul 13, 2025Updated last year
- 基于UC的启发式杀毒引擎[还没做完]☆37Mar 28, 2021Updated 5 years ago
- ☆18Jun 16, 2025Updated last year
- Collect Windows telemetry for Maldev☆508Aug 14, 2026Updated last month
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- SafeHarbor revamped with Direct Syscalls using InlineWhispers3☆14Feb 16, 2026Updated 7 months ago
- Sanctum is an experimental proof-of-concept EDR, designed to detect modern malware techniques, above and beyond the capabilities of antiv…☆567Mar 24, 2026Updated 6 months ago
- libdt is part of the "Huorong eXtendible Stream Scan Engine" project copyright by Huorong Borui (Beijing) Technology Co., Ltd.☆14Aug 17, 2015Updated 11 years ago
- https://key08.com/index.php/2021/10/19/1375.html☆69May 11, 2022Updated 4 years ago
- Extracted Yara rules from Windows Defender mpavbase and mpasbase☆539May 14, 2026Updated 4 months ago
- 通过分析流量,快速检查手机是否被APT攻击☆35Oct 19, 2025Updated 11 months ago
- ☆26Jul 15, 2023Updated 3 years ago
- Implementing an early exception handler for hooking and threadless process injection without relying on VEH or SEH☆140Aug 31, 2025Updated last year
- defender_database☆24Oct 31, 2023Updated 2 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Self Cleanup in post-ex job☆58Sep 10, 2024Updated 2 years ago
- Uses ghidra to find all ETW write metadata for each API in a PE file☆32Jul 26, 2024Updated 2 years ago
- ForsHops☆58Mar 25, 2025Updated last year
- The first Computer Emergency Response (ARK) Tools for young people ;) 年轻人的第一款应急响应(ARK)工具 ;)☆688Oct 21, 2025Updated 11 months ago
- 通杀检测基于白文件patch黑代码的免杀技术的后门☆182Aug 3, 2024Updated 2 years ago
- Ryūjin Protector - Is a Intel Arch - BIN2BIN - PE Obfuscation/Protection/DRM tool☆348Nov 20, 2025Updated 10 months ago
- ☆19Jul 31, 2026Updated last month
- Remove AV/EDR Kernel ObRegisterCallbacks、CmRegisterCallback、MiniFilter Callback、PsSetCreateProcessNotifyRoutine Callback、PsSetCreateThrea…☆1,325Jun 21, 2024Updated 2 years ago
- Simulate per-process disconnection in red team environments☆115Jun 6, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A modern C++20 header-only library for advanced direct system call invocation.☆181Sep 5, 2026Updated 3 weeks ago
- Usermode exploit to bypass any AC using a 0day shatter attack.☆390Nov 26, 2025Updated 10 months ago
- Peach Fuzzer漏洞挖掘实战☆23Jul 6, 2023Updated 3 years ago
- GateSentinel 是一个现代化的 C2 (Command and Control) 框架,专为安全研究和渗透测试设计。该项目采用 Go 语言开发服务端,C 语言开发客户端,提供了强大的远程控制和管理功能。☆289Jul 17, 2025Updated last year
- 在线安软识别☆11Aug 6, 2025Updated last year
- Lightweight, dependency-free x86-64 CPU emulation library with Unicorn-like guest mode and direct host-memory execution.☆232May 11, 2026Updated 4 months ago
- PoC memory injection detection agent based on ETW, for offensive and defensive research purposes☆299Apr 10, 2021Updated 5 years ago
- A tool for automatic patch shellcode into binary file to bypass AV. / 一个自动patch shellcode到二进制文件的工具☆583Sep 17, 2026Updated last week
- A simple Sleepmask BOF example☆177Nov 24, 2025Updated 10 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules☆220Updated this week
- Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials☆54May 12, 2025Updated last year
- HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.☆737Jul 19, 2023Updated 3 years ago
- 使用 Intel 虚拟化特性实现应用层HOOK☆65Sep 11, 2025Updated last year
- A Blind EDR Project for Educational Purposes☆107Jan 18, 2025Updated last year
- 一款linux下的安全产品目的是满足个人安全需求有SSH爆破防护和SYN攻击扫描防护功能,基于netfilter,☆23Dec 2, 2023Updated 2 years ago
- Just another version of the custom stack call from Proxy-Function-Calls-For-ETwTI☆34Mar 17, 2023Updated 3 years ago