pathtofile / SimpleAmsiProvider
A simple provider to analyse what gets passed into Microsoft's Anti-Malware Scan Interface
☆13Updated 5 years ago
Alternatives and similar repositories for SimpleAmsiProvider:
Users that are interested in SimpleAmsiProvider are comparing it to the libraries listed below
- A tool to create COM class/interface relationships in neo4j☆47Updated 2 years ago
- ☆24Updated 3 years ago
- ☆28Updated 7 years ago
- Experiments on the Windows Internals☆30Updated 5 years ago
- ☆46Updated 3 years ago
- C# code to run PIC using CreateThread☆16Updated 5 years ago
- ☆14Updated 4 years ago
- ☆45Updated 6 years ago
- The repository accompanying the Buer Emulation workshop☆24Updated 3 years ago
- Dump Lsass Memory Using a Reflective Dll☆14Updated 2 years ago
- Simple tool to use LsaManageSidNameMapping get LSA to add or remove SID to name mappings.☆23Updated 4 years ago
- Retrieve the IIS Application Pool Credentials. Relies on the WebAdministration PowerShell Module.☆13Updated 7 years ago
- POC code to crash Windows Event Logger Service☆26Updated 4 years ago
- Proof of concept - Covert Channel using Windows Filtering Platform (C#)☆21Updated 3 years ago
- Create a Run registry key with direct system calls. Inspired by @Cneelis's Dumpert and SharpHide.☆74Updated 4 years ago
- Protect your servers with a secret header☆28Updated 4 years ago
- ☆15Updated 3 years ago
- Tool to manage user privileges☆28Updated 5 years ago
- A set of commands to bypass Defender (and some other AVs)☆20Updated 5 years ago
- PoC code from blog☆16Updated 4 years ago
- ☆31Updated 4 years ago
- AMSI detection PoC☆30Updated 4 years ago
- AppXSVC Service race condition - privilege escalation☆27Updated 5 years ago
- Rapidly building a Windows 10 system to use for dynamic malware analysis (sandbox), sending data to Elastic Cloud.☆46Updated last year
- A spiritual .NET equivalent to the Gargoyle memory scanning evasion technique☆51Updated 6 years ago
- ☆20Updated 3 years ago
- ☆26Updated 6 years ago
- A Practical example of ELAM (Early Launch Anti-Malware)☆33Updated 3 years ago
- Ingests logs/dbs from cobalt and empire and outputs an excel report with activity, sessions, and credentials☆20Updated 4 years ago
- ☆11Updated 5 years ago