inb1ts / birdnet-poc
Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.
☆38Updated last year
Related projects ⓘ
Alternatives and complementary repositories for birdnet-poc
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated 3 months ago
- Click Once + App Domain☆62Updated 11 months ago
- ☆27Updated 5 months ago
- Beacon Object Files (not Buffer Overflows)☆51Updated last year
- ☆47Updated last year
- DLL proxy load example using the Windows thread pool API, I/O completion callback with named pipes, and C++/assembly☆54Updated 7 months ago
- BOF for C2 framework☆40Updated this week
- ☆59Updated 3 months ago
- I have documented all of the AMSI patches that I learned till now☆68Updated last year
- A VSCode devcontainer for development of COFF files with batteries included.☆47Updated last year
- ☆27Updated 2 months ago
- ☆38Updated last year
- Python3 rewrite of AsOutsider features of AADInternals