loosehose / SilentButDeadlyView external linksLinks
SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using Windows Filtering Platform (WFP). This version focuses solely on network isolation without process termination.
☆433Nov 3, 2025Updated 3 months ago
Alternatives and similar repositories for SilentButDeadly
Users that are interested in SilentButDeadly are comparing it to the libraries listed below
Sorting:
- SOCKS5 proxy tool that uses Azure Blob Storage as a means of communication.☆287Apr 29, 2025Updated 9 months ago
- Local SYSTEM auth trigger for relaying☆168Jul 22, 2025Updated 6 months ago
- Proof of Concept (PoC) .NET tool for remotely killing EDR with WDAC☆418Sep 29, 2025Updated 4 months ago
- This is the tool to dump the LSASS process on modern Windows 11☆555Nov 1, 2025Updated 3 months ago
- Weaponizing DCOM for NTLM Authentication Coercions☆275Jul 1, 2025Updated 7 months ago
- ☆235Oct 8, 2024Updated last year
- DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely☆381Dec 13, 2024Updated last year
- BOF with Synthetic Stackframe☆220Oct 30, 2025Updated 3 months ago
- A BOF that's a BOF Loader and more☆196Jan 17, 2026Updated 3 weeks ago
- Lateral Movement via Bitlocker DCOM interfaces & COM Hijacking☆433Jun 27, 2025Updated 7 months ago
- Dig your way out of networks like a Meerkat using SSH tunnels via ClickOnce.☆264May 2, 2025Updated 9 months ago
- Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry☆457Aug 2, 2024Updated last year
- A POC to disable TamperProtection and other Defender / MDE components☆254Jun 6, 2024Updated last year
- Evasive shellcode loader☆398Oct 17, 2024Updated last year
- A C# utility for interacting with SCOM☆95Dec 2, 2025Updated 2 months ago
- Robust Cobalt Strike shellcode loader with multiple advanced evasion features☆199Apr 21, 2025Updated 9 months ago
- Cobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from si…☆34Feb 6, 2026Updated last week
- Cobalt Strike UDC2 implementation that provides an Slack C2 channel☆60Jan 5, 2026Updated last month
- Enumerate Domain Users Without Authentication☆281Apr 22, 2025Updated 9 months ago
- .NET Post-Exploitation Utility for Abusing Strong Explicit Certificate Mappings in ADCS☆150Feb 10, 2025Updated last year
- EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.☆801Nov 1, 2025Updated 3 months ago
- This is the loader that supports running a program with Protected Process Light (PPL) protection functionality.☆294Nov 1, 2025Updated 3 months ago
- Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)☆698May 7, 2025Updated 9 months ago
- Early Bird Cryo Injections – APC-based DLL & Shellcode Injection via Pre-Frozen Job Objects☆135Apr 6, 2025Updated 10 months ago
- psexecsvc - a python implementation of PSExec's native service implementation☆235Feb 11, 2025Updated last year
- RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging☆203Mar 6, 2025Updated 11 months ago
- A C++ proof of concept demonstrating the exploitation of Windows Protected Process Light (PPL) by leveraging COM-to-.NET redirection and …☆332Mar 6, 2025Updated 11 months ago
- Bypass user-land hooks by syscall tampering via the Trap Flag☆139Aug 25, 2025Updated 5 months ago
- COM-based DLL Surrogate Injection☆140Dec 9, 2025Updated 2 months ago
- Ghosting-AMSI☆222Apr 24, 2025Updated 9 months ago
- BOF that finds all the Nt* system call stubs within NTDLL and overwrites with clean syscall stubs (user land hook evasion)☆195Feb 6, 2025Updated last year
- ☆198Mar 28, 2025Updated 10 months ago
- malware written for educational purposes☆71Dec 31, 2025Updated last month
- A PowerShell console in C/C++ with all the security features disabled☆342Oct 14, 2025Updated 4 months ago
- Waiting Thread Hijacking - injection by overwriting the return address of a waiting thread☆262Aug 31, 2025Updated 5 months ago
- Run native PE or .NET executables entirely in-memory. Build the loader as an .exe or .dll—DllMain is Cobalt Strike UDRL-compatible☆266Jun 18, 2025Updated 7 months ago
- ForsHops☆152Mar 25, 2025Updated 10 months ago
- A Rust implementation of GodPotato — abusing SeImpersonate to gain SYSTEM privileges. Includes a TCP-based reverse shell and indirect NTA…☆355Apr 26, 2025Updated 9 months ago
- ☆86Jan 21, 2025Updated last year