Another version of .NET loader provides capabilities of bypassing ETW and AMSI, utilizing VEH for syscalls and loading .NET assemblies
☆50Jul 6, 2025Updated last year
Alternatives and similar repositories for VEHNetLoader
Users that are interested in VEHNetLoader are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A proof of concept AMSI & ETW bypass using trampolines for hooking and modifying execution flow☆19Jun 26, 2025Updated last year
- ☆55Oct 13, 2025Updated 11 months ago
- A Windows 11 Rootkit. (Exploit has been patched)☆17Sep 7, 2025Updated last year
- Bypassing Amsi using LdrLoadDll☆47Jan 8, 2025Updated last year
- .NET assembly loader with patching AMSI and ETW bypass☆33Apr 16, 2025Updated last year
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A version of NetLoader, Execute Assemblies and Bypass ETW and AMSI using Hardware Breakpoints☆131Jul 11, 2025Updated last year
- Zero dependency browser extension for handling import of cookies, Microsoft 365 OAuth tokens, and Graph API interactions.☆39Jun 5, 2026Updated 4 months ago
- Utilizng an MCP Server to communicate with your C2☆94May 15, 2025Updated last year
- A user-mode code and its rootkit that will Kill EDR Processes permanently by leveraging the power of Process Creation Blocking Kernel Cal…☆265Jun 10, 2025Updated last year
- inspired by mr d0x filefix☆16Feb 4, 2026Updated 8 months ago
- Locate dlls and function addresses without PEB Walk and EAT parsing☆109Nov 7, 2025Updated 11 months ago
- kASLR bypass technique on Intel CPUs.☆35May 18, 2025Updated last year
- Performs a global AMSI bypass by patching amsi.dll in memory.☆21Oct 14, 2025Updated 11 months ago
- Bypass user-land hooks by syscall tampering via the Trap Flag☆141Aug 25, 2025Updated last year
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Implementing an early exception handler for hooking and threadless process injection without relying on VEH or SEH☆139Aug 31, 2025Updated last year
- Build sneaky & malicious LNK files.☆162Jul 16, 2025Updated last year
- HardwareTurningPoint, Fully Go Compatible Hardware Breakpoint☆15Jan 30, 2025Updated last year
- Just a nice little shellcode loader using unconventional methods to avoid using signatured APIs☆26Jul 11, 2025Updated last year
- ☆19Jan 8, 2026Updated 9 months ago
- A BOF that's a BOF Loader and more☆212Apr 6, 2026Updated 6 months ago
- ☆402Jun 13, 2025Updated last year
- ☆32Oct 19, 2024Updated last year
- extract chromium-based browser's cookies using chrome's remote debugging without admin rights☆23Nov 3, 2024Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Obex – Blocking unwanted DLLs in user mode☆279Sep 18, 2025Updated last year
- A 64 bit executable junk code engine for polymorphic malware.☆81Jun 16, 2025Updated last year
- Executing Kernel Routines via Syscall Table Hijack (Kernel Code Execution)☆84Jun 7, 2026Updated 4 months ago
- ☆31Aug 23, 2020Updated 6 years ago
- Anti-Debugging (Self-Debugging)☆17Sep 6, 2025Updated last year
- Commandline spoofing on Windows☆99Jul 19, 2026Updated 2 months ago
- **CVE-2026-2636** is a vulnerability in the Windows Common Log File System (CLFS) driver (`CLFS.sys`). An unprivileged user can trigger a…☆15Feb 26, 2026Updated 7 months ago
- HookChain: A new perspective for Bypassing EDR Solutions☆613Jan 5, 2025Updated last year
- Local SYSTEM auth trigger for relaying - X☆160Jul 23, 2025Updated last year
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Generate an Alphabetical Polymorphic Shellcode☆147Aug 19, 2025Updated last year
- Fairy Law - Compromise or disable EDR security solutions☆79Dec 1, 2025Updated 10 months ago
- Sh3ller is a lightweight C2 framework in its simplest form.☆33Sep 5, 2025Updated last year
- Permanently disable EDRs as local admin☆131Dec 19, 2025Updated 9 months ago
- Lightweight Patchless Hooking Library for Windows☆19Dec 31, 2025Updated 9 months ago
- template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.☆106Jan 10, 2026Updated 8 months ago
- Dynamic shellcode loader with sophisticated evasion capabilities☆344Oct 1, 2025Updated last year