oldkingcone / BYOSI
Evade EDR's the simple way, by not touching any of the API's they hook.
☆49Updated 3 months ago
Related projects ⓘ
Alternatives and complementary repositories for BYOSI
- Two in one, patch lifetime powershell console, no more etw and amsi!☆80Updated 4 months ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆47Updated 8 months ago
- Lateral Movement via the .NET Profiler☆76Updated 5 months ago
- Just another C2 Redirector using CloudFlare.☆78Updated 6 months ago
- Example code samples from our ScriptBlock Smuggling Blog post☆83Updated 5 months ago
- ☆126Updated 3 months ago
- A tool to modify SCCM remote control settings on the client machine, enabling remote control without permission prompts or notifications.…☆74Updated last month
- Construct the payload at runtime using an array of offsets☆58Updated 5 months ago
- ☆92Updated 8 months ago
- ☆58Updated 11 months ago
- A variation of ProcessOverwriting to execute shellcode on an executable's section☆145Updated 11 months ago
- A web assembly (WASM) phishing lure generator based on pre-built templates and written in Rust with some GenAI assistance. W.A.L.K. aims …☆59Updated 2 months ago
- ☆103Updated 6 months ago
- Public repo of some woking evilginx phishlets☆21Updated 2 weeks ago
- Windows Thread Pool Injection Havoc Implementation☆28Updated 7 months ago
- .NET assembly loader with patchless AMSI and ETW bypass in Rust☆29Updated last month
- C++ Staged Shellcode Loader with Evasion capabilities.☆73Updated last month
- Interactive Shell and Command Execution over Named-Pipes (SMB) for Fileless lateral movement☆88Updated last month
- TokenCert☆83Updated this week
- ☆73Updated last year
- Identify common EDR processes, directories, and services. Simple BOF of Invoke-EDRChecker.☆108Updated last month
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated 4 months ago
- Lifetime AMSI bypass.☆36Updated 4 months ago
- BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR☆72Updated 9 months ago
- ☆87Updated 2 months ago
- Reasonably undetected shellcode stager and executer.☆35Updated 2 months ago
- Source code and examples for PassiveAggression☆54Updated 5 months ago
- ☆118Updated last year
- A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders Stardust☆82Updated 7 months ago
- The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning☆78Updated 7 months ago