myzxcg / RealBlindingEDRLinks
Remove AV/EDR Kernel ObRegisterCallbacks、CmRegisterCallback、MiniFilter Callback、PsSetCreateProcessNotifyRoutine Callback、PsSetCreateThreadNotifyRoutine Callback、PsSetLoadImageNotifyRoutine Callback...
☆1,092Updated last year
Alternatives and similar repositories for RealBlindingEDR
Users that are interested in RealBlindingEDR are comparing it to the libraries listed below
Sorting:
- darkPulse是一个用go编写的shellcode Packer,用于生成各种各样的shellcode loader,免杀火绒,360核晶等国内常见杀软。☆850Updated 8 months ago
- 一个手动或自动patch shellcode到二进制文件的免杀工具/A tool for manual or automatic patch shellcode into binary file oder to bypass AV.☆516Updated last month
- Windows Elevation(持续更新)☆657Updated 3 years ago
- 牛屎花 一款基于WEB界面的远程主机管理工具☆837Updated 2 years ago
- CobaltStrike Beacon written in .Net 4 用.net重写了stager及Beacon,其中包括正常上线、文件管理、进程管理、令牌管理、结合SysCall进行注入、原生端口转发、关ETW等一系列功能☆722Updated 3 years ago
- 免杀,bypassav,免杀框架,nim,shellcode,使用nim编写的shellcode加载器☆661Updated 4 months ago
- C2-下一代RAT☆432Updated 11 months ago
- RedGuard is a C2 front flow control tool,Can avoid Blue Teams,AVs,EDRs check.☆1,492Updated 10 months ago
- not a reverse-engineered version of the Cobalt Strike Beacon☆374Updated last year
- CobaltStrike beacon written in golang☆436Updated last year
- CPP AV/EDR Killer☆425Updated last year
- Some demos to bypass EDRs or AVs by 78itsT3@m☆353Updated 3 years ago
- Open repository for learning dynamic shellcode loading (sample in many programming languages)☆251Updated 2 weeks ago
- New generation of wmiexec.py☆1,112Updated last month
- Alternative Shellcode Execution Via Callbacks☆1,594Updated 2 years ago
- 绕3环的shellcode免杀框架☆572Updated 4 years ago
- Use ICMLuaUtil to Bypass UAC!☆565Updated 5 years ago
- Windows 权限提升 BadPotato☆852Updated 5 years ago
- This is my FirstRepository☆334Updated 2 years ago
- SysWhispers on Steroids - AV/EDR evasion via direct system calls.☆1,461Updated 11 months ago
- 一个浏览器数据(密码|历史记录|Cookie|书签|下载记录)的导出工具,支持主流浏览器。☆729Updated 8 months ago
- Hunts out CobaltStrike beacons and logs operator command output☆932Updated 10 months ago
- 免杀远控木马源码整理开源(银 狐 winos 大灰狼 gh0st) Rat☆441Updated 6 months ago
- POCs for Shellcode Injection via Callbacks☆409Updated 4 years ago
- Sign-Sacker(签名掠夺者):一款数字签名复制器,可将其他官方exe中数字签名,图标,详细信息复制到没有签名的exe中,作为免杀,权限维持,伪装的一种小手段。☆572Updated last year
- windows-rs shellcode loaders☆359Updated last year
- 免杀知识库 | 开源免杀木马效果测试 360 火绒 卡巴斯基 Microsoft Defender | 免杀工具汇总☆268Updated 3 weeks ago
- 助力每一位RT队员,快速生成免杀木马☆784Updated last year
- Windows Token Stealing Expert☆473Updated last year
- 寻找可利用的白文件☆520Updated last year