PoC exploit for the vulnerable WatchDog Anti-Malware driver (amsdk.sys) – weaponized to kill protected EDR/AV processes via BYOVD.
☆202Sep 11, 2025Updated 5 months ago
Alternatives and similar repositories for WatchDogKiller
Users that are interested in WatchDogKiller are comparing it to the libraries listed below
Sorting:
- Bypassing Amsi using LdrLoadDll☆47Jan 8, 2025Updated last year
- Proof-of-concept implementation of AI-enabled postex DLLs☆54Sep 10, 2025Updated 5 months ago
- Obex – Blocking unwanted DLLs in user mode☆282Sep 18, 2025Updated 5 months ago
- This is the tool to dump the LSASS process on modern Windows 11☆560Nov 1, 2025Updated 4 months ago
- Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird …☆779Jan 26, 2026Updated last month
- NSecSoftBYOVD POC☆58Feb 12, 2026Updated 3 weeks ago
- Permanently disable EDRs as local admin☆127Dec 19, 2025Updated 2 months ago
- Implementing an early exception handler for hooking and threadless process injection without relying on VEH or SEH☆140Aug 31, 2025Updated 6 months ago
- Tool to bypass LSA Protection (aka Protected Process Light)☆64Jan 2, 2025Updated last year
- Dump cookies and credentials directly from Chrome/Edge process memory☆1,410Jan 19, 2026Updated last month
- A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike☆187Oct 29, 2025Updated 4 months ago
- UAC Bypass using UIAccess program QuickAssist☆217Nov 30, 2025Updated 3 months ago
- AppLocker-Based EDR Neutralization☆323Dec 19, 2025Updated 2 months ago
- BYOVD: Use 360 WFP driver to block EDR/XDR network connection.☆103Feb 10, 2026Updated 3 weeks ago
- UAC bypass by abusing RPC and debug objects.☆627Oct 19, 2023Updated 2 years ago
- A POC to disable TamperProtection and other Defender / MDE components☆255Jun 6, 2024Updated last year
- Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but fo…☆167Oct 21, 2025Updated 4 months ago
- COM-based DLL Surrogate Injection☆142Dec 9, 2025Updated 2 months ago
- A BOF that's a BOF Loader and more☆199Jan 17, 2026Updated last month
- Collection of Beacon Object Files (BOF) for Cobalt Strike☆677Aug 15, 2025Updated 6 months ago
- 🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications☆1,297Jun 17, 2025Updated 8 months ago
- Crystal Palace library for proxying Nt API calls via the Threadpool☆100Oct 18, 2025Updated 4 months ago
- Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)☆701May 7, 2025Updated 10 months ago
- CVE-2024-40431+CVE-2022-25479 chain for EOP(DATA ONLY ATTACK)☆45Oct 16, 2024Updated last year
- A beacon object file implementation of PoolParty Process Injection Technique.☆435Dec 21, 2023Updated 2 years ago
- EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.☆807Nov 1, 2025Updated 4 months ago
- Process injection alternative☆406Sep 6, 2024Updated last year
- Exploiting the KsecDD Windows driver through Server Silos☆77Nov 11, 2024Updated last year
- Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)☆262Jun 29, 2024Updated last year
- Port of Cobalt Strike's Process Inject Kit☆192Dec 1, 2024Updated last year
- ☆50Jun 4, 2025Updated 9 months ago
- ☆409Dec 8, 2024Updated last year
- HVNC PoC (Hidden VNC) in Rust☆40Sep 2, 2025Updated 6 months ago
- ☆26Dec 13, 2024Updated last year
- Threadless Process Injection using remote function hooking.☆810Sep 4, 2024Updated last year
- Robust Cobalt Strike shellcode loader with multiple advanced evasion features☆200Apr 21, 2025Updated 10 months ago
- Proof of Concept (PoC) .NET tool for remotely killing EDR with WDAC☆424Sep 29, 2025Updated 5 months ago
- BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055,).☆595Feb 24, 2026Updated last week
- DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely☆382Dec 13, 2024Updated last year