Another version of .NET loader provides capabilities of bypassing ETW and AMSI, utilizing VEH for syscalls and loading .NET assemblies
☆50Jul 6, 2025Updated last year
Alternatives and similar repositories for VEHNetLoader
Users that are interested in VEHNetLoader are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A proof of concept AMSI & ETW bypass using trampolines for hooking and modifying execution flow☆19Jun 26, 2025Updated last year
- ☆55Oct 13, 2025Updated 9 months ago
- A Windows 11 Rootkit. (Exploit has been patched)☆16Sep 7, 2025Updated 10 months ago
- Bypassing Amsi using LdrLoadDll☆48Jan 8, 2025Updated last year
- A version of NetLoader, Execute Assemblies and Bypass ETW and AMSI using Hardware Breakpoints☆129Jul 11, 2025Updated last year
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Utilizng an MCP Server to communicate with your C2☆95May 15, 2025Updated last year
- A user-mode code and its rootkit that will Kill EDR Processes permanently by leveraging the power of Process Creation Blocking Kernel Cal…☆265Jun 10, 2025Updated last year
- Zero dependency browser extension for handling import of cookies, Microsoft 365 OAuth tokens, and Graph API interactions.☆35Jun 5, 2026Updated last month
- inspired by mr d0x filefix☆16Feb 4, 2026Updated 5 months ago
- Locate dlls and function addresses without PEB Walk and EAT parsing☆110Nov 7, 2025Updated 8 months ago
- Performs a global AMSI bypass by patching amsi.dll in memory.☆18Oct 14, 2025Updated 9 months ago
- kASLR bypass technique on Intel CPUs.☆34May 18, 2025Updated last year
- Bypass user-land hooks by syscall tampering via the Trap Flag☆140Aug 25, 2025Updated 10 months ago
- Misery Loader to bypass modern EDR solutions☆19Dec 20, 2024Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Implementing an early exception handler for hooking and threadless process injection without relying on VEH or SEH☆139Aug 31, 2025Updated 10 months ago
- Build sneaky & malicious LNK files.☆161Jul 16, 2025Updated last year
- HardwareTurningPoint, Fully Go Compatible Hardware Breakpoint☆14Jan 30, 2025Updated last year
- Just a nice little shellcode loader using unconventional methods to avoid using signatured APIs☆23Jul 11, 2025Updated last year
- ☆20Jan 8, 2026Updated 6 months ago
- Yet another shellcode loader - but a sneaky one☆26Apr 16, 2025Updated last year
- A Mythic agent for Windows written in C☆170Updated this week
- A BOF that's a BOF Loader and more☆209Apr 6, 2026Updated 3 months ago
- ☆29Oct 19, 2024Updated last year
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- ☆403Jun 13, 2025Updated last year
- extract chromium-based browser's cookies using chrome's remote debugging without admin rights☆22Nov 3, 2024Updated last year
- Obex – Blocking unwanted DLLs in user mode☆279Sep 18, 2025Updated 10 months ago
- A 64 bit executable junk code engine for polymorphic malware.☆78Jun 16, 2025Updated last year
- Executing Kernel Routines via Syscall Table Hijack (Kernel Code Execution)☆82Jun 7, 2026Updated last month
- ☆31Aug 23, 2020Updated 5 years ago
- Anti-Debugging (Self-Debugging)☆17Sep 6, 2025Updated 10 months ago
- Commandline spoofing on Windows☆100Updated this week
- **CVE-2026-2636** is a vulnerability in the Windows Common Log File System (CLFS) driver (`CLFS.sys`). An unprivileged user can trigger a…☆15Feb 26, 2026Updated 4 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- HookChain: A new perspective for Bypassing EDR Solutions☆609Jan 5, 2025Updated last year
- Generate an Alphabetical Polymorphic Shellcode☆145Aug 19, 2025Updated 11 months ago
- Local SYSTEM auth trigger for relaying - X☆159Jul 23, 2025Updated 11 months ago
- Fairy Law - Compromise or disable EDR security solutions☆79Dec 1, 2025Updated 7 months ago
- Sh3ller is a lightweight C2 framework in its simplest form.☆33Sep 5, 2025Updated 10 months ago
- Stealthy x64 thread manipulation library for calling functions inside target processes without creating remote threads or installing hook…☆59Oct 10, 2025Updated 9 months ago
- Robust Cobalt Strike shellcode loader with multiple advanced evasion features☆206Apr 21, 2025Updated last year