magicsword-io / LOLDriversLinks
Living Off The Land Drivers
☆1,346Updated this week
Alternatives and similar repositories for LOLDrivers
Users that are interested in LOLDrivers are comparing it to the libraries listed below
Sorting:
- ☆1,759Updated last year
- EDR Lab for Experimentation Purposes☆1,387Updated last month
- A set of fully-undetectable process injection techniques abusing Windows Thread Pools☆1,215Updated 2 years ago
- The multi-platform memory acquisition tool.☆900Updated last month
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆790Updated last year
- A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the …☆1,784Updated last year
- Project for tracking publicly disclosed DLL Hijacking opportunities.☆846Updated last month
- ☆2,164Updated 2 years ago
- PoCs and tools for investigation of Windows process execution techniques☆945Updated last month
- Win32 and Kernel abusing techniques for pentesters☆967Updated 2 years ago
- A modern 32/64-bit position independent implant template☆1,268Updated 8 months ago
- Spartacus DLL/COM Hijacking Toolkit☆1,072Updated last year
- A tool to kill antimalware protected processes☆1,484Updated 4 years ago
- Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes☆1,035Updated 2 years ago
- A memory-based evasion technique which makes shellcode invisible from process start to end.☆1,196Updated 2 years ago
- Original C Implementation of the Hell's Gate VX Technique☆1,136Updated 4 years ago
- Hardcore Debugging☆925Updated 3 months ago
- ☆774Updated 2 years ago
- ☆514Updated last year
- Dynamic unpacker based on PE-sieve☆783Updated 2 months ago
- SysWhispers on Steroids - AV/EDR evasion via direct system calls.☆1,540Updated last year
- Nidhogg is an all-in-one simple to use windows kernel rootkit.☆2,153Updated last week
- Collection of various malicious functionality to aid in malware development☆1,801Updated last year
- AV/EDR evasion via direct system calls.☆1,762Updated 3 years ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆688Updated last month
- Elastic Security detection content for Endpoint☆1,338Updated this week
- ☆607Updated last month
- SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also conta…☆470Updated 5 months ago
- A tool that takes over Windows Updates to craft custom downgrades and expose past fixed vulnerabilities☆689Updated last year
- Awesome EDR Bypass Resources For Ethical Hacking☆1,357Updated last month