jm33-m0 / windows-sandbox-init
Rapidly initialize Windows Sanbox for malware analysis and reverse engineering
☆131Updated 3 months ago
Alternatives and similar repositories for windows-sandbox-init
Users that are interested in windows-sandbox-init are comparing it to the libraries listed below
Sorting:
- A command and control framework written in rust.☆343Updated 2 months ago
- This repository contains POC scenarios as part of CVE-2025-0411 MotW bypass.☆131Updated 2 months ago
- ☆301Updated 6 months ago
- Nameless C2 - A C2 with all its components written in Rust☆266Updated 7 months ago
- Windows Persistence IT-Security☆100Updated 2 months ago
- Simulate the behavior of AV/EDR for malware development training.☆524Updated last year
- Shadow Dumper is a powerful tool used to dump LSASS memory, often needed in penetration testing and red teaming. It uses multiple advance…☆533Updated last month
- Proof of Concept (PoC) .NET tool for remotely killing EDR with WDAC☆355Updated 4 months ago
- Invoke-ArgFuscator is an open-source, cross-platform PowerShell module that helps generate obfuscated command-lines for common system-nat…☆171Updated last month
- A new technique that can be used to bypass memory scanners. This can be useful in hiding problematic code (such as reflective loaders imp…☆308Updated 7 months ago
- ☆356Updated 5 months ago
- kernel callback removal (Bypassing EDR Detections)☆162Updated last month
- A sophisticated, covert Windows-based credential dumper using C++ and MASM x64.☆408Updated 10 months ago
- A collection of tools and detections for the Sliver C2 Frameworj☆126Updated 2 years ago
- Just a simple silly PoC demonstrating executable "exe" file that can be used like exe, dll or shellcode...☆156Updated 8 months ago
- Fully functional, from-scratch alternative to the Cobalt Strike Beacon (red teaming tool), offering transparency and flexibility for secu…☆227Updated last year
- ☆187Updated last year
- Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry☆409Updated 9 months ago
- CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File☆278Updated last month
- Leverage WindowsApp createdump tool to obtain an lsass dump☆149Updated 7 months ago
- lolC2 is a collection of C2 frameworks that leverage legitimate services to evade detection☆204Updated 2 weeks ago
- CPP AV/EDR Killer☆410Updated last year
- Windows remote execution multitool☆476Updated last week
- Red teaming tool to dump LSASS memory, bypassing basic countermeasures.☆227Updated 4 months ago
- PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges requir…☆148Updated 11 months ago
- Reproducing Spyboy technique, which involves terminating all EDR/XDR/AVs processes by abusing the zam64.sys driver☆273Updated 3 weeks ago
- Privilege escalation using the XAML diagnostics API (CVE-2023-36003)☆92Updated last year
- Proof of concept & details for CVE-2025-21298☆180Updated 3 months ago
- A delicious, but malicious SSL-VPN server 🌮☆219Updated 5 months ago
- StoneKeeper C2, an experimental EDR evasion framework for research purposes☆201Updated 4 months ago