p1d3er / Go2bypass
Golang 写的免杀框架,通过系统调用等手法bypass AV/EDR
☆22Updated 9 months ago
Alternatives and similar repositories for Go2bypass:
Users that are interested in Go2bypass are comparing it to the libraries listed below
- xiebroC2 plugin☆45Updated last month
- Hidedump:a lsassdump tools that may bypass EDR☆50Updated 10 months ago
- 绕过defender的完整项目☆33Updated last year
- Zerologon自动化脚本☆88Updated last year
- 用于解密并加载shellcode,支持RC4和AES两种解密方法,并使用DInvoke来动态调用WinAPI函数,从而尝试绕过某些安全解决方案☆28Updated last year
- Confluence后台rce☆19Updated last year
- Shellcode Reductio Entropy Tools☆66Updated last year
- 一个2020年练手的基于gin框架搞的在线免杀平台,支持后台管理,邀请码注册等☆38Updated 7 months ago
- ☆43Updated 4 months ago
- cobaltstrike的BypassUAC、提权dll插件☆81Updated 4 months ago
- CVE-2024-20931, this is the bypass of the patch of CVE-2023-21839☆61Updated last year
- FTP lnk调用pythonw程序,用于攻防钓鱼场景下免杀运行捆绑木马文件☆61Updated 7 months ago
- Confluence未授权添加管理员用户(CVE-2023-22515)漏洞利用工具☆107Updated last year
- 根据攻防以及域信息收集经验dump快而有用的域信息☆104Updated last year
- Zerologon exploit with restore DC password automatically☆133Updated last year
- ☆33Updated last year
- Red team tool designed for quickly identifying hijackable programs, evading antivirus software, and EDR (Endpoint Detection and Response)…☆65Updated last month
- 利用EFSRPC协议批量探测出网☆65Updated last year
- EWSTool是一个针对EXCHANGE邮件服务器的后渗透利用工具。使用ews接口,实现人员邮箱列表获取、搜索邮件、下载邮件等实用功能。☆49Updated last month
- ☆26Updated 3 years ago
- golang styles proxy client, support http/https, socks4/5, ssh☆30Updated last week
- go实现的shellcode免杀加载器,实测时可过火绒,360。当前效果请自行评判。☆33Updated 7 months ago
- ☆49Updated last year
- 集权利用工具☆55Updated last month
- AutoGeaconC2: 一键读取Profile自动化生成geacon实现跨平台上线CobaltStrike☆141Updated last year
- 集成了截图 键盘记录 剪贴版功能,用于网络限制场景下的信息搜集☆82Updated 11 months ago
- 新免杀方向 Mimikatz(猕猴桃) 免杀 360,火绒,电脑管家,WindowsDefinder,详细使用教程请参考博客:https://www.vpss.cc/381.html☆23Updated last year
- File entropy calculator - Golang☆26Updated last year
- powershell免杀混淆器,简单有效。A simple and effective powershell obfuscaiton tool bypass Anti-Virus☆14Updated 2 years ago
- 主要用于隐藏进程真实路径,进程带windows真签名☆109Updated 6 months ago