rad9800 / FileRenameJunctionsEDRDisable
☆143Updated 2 months ago
Alternatives and similar repositories for FileRenameJunctionsEDRDisable:
Users that are interested in FileRenameJunctionsEDRDisable are comparing it to the libraries listed below
- ☆139Updated 6 months ago
- ☆180Updated last year
- Two in one, patch lifetime powershell console, no more etw and amsi!☆83Updated 7 months ago
- Shellcode loader☆76Updated 2 months ago
- ☆94Updated last month
- Port of Cobalt Strike's Process Inject Kit☆165Updated 2 months ago
- An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution☆172Updated 2 months ago
- AzureAD beacon object files☆109Updated 2 months ago
- Construct the payload at runtime using an array of offsets☆61Updated 8 months ago
- Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination…☆141Updated 6 months ago
- ☆122Updated 5 months ago
- "Service-less" driver loading☆149Updated 2 months ago
- A Mythic Agent written in PIC C.☆171Updated 2 weeks ago
- Bypass Credential Guard by patching WDigest.dll using only NTAPI functions☆216Updated 2 months ago
- This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone…☆185Updated 4 months ago
- ☆147Updated last year
- A set of programs for analyzing common vulnerabilities in COM☆193Updated 5 months ago
- Do some DLL SideLoading magic☆78Updated last year
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆73Updated 6 months ago
- Bypass LSA protection using the BYODLL technique☆154Updated 4 months ago
- DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.☆96Updated last year
- Flexible LDAP proxy that can be used to inspect & transform all LDAP packets generated by other tools on the fly.☆104Updated 2 months ago
- A variation of ProcessOverwriting to execute shellcode on an executable's section☆147Updated last year
- TypeLib persistence technique☆107Updated 3 months ago
- Just another C2 Redirector using CloudFlare.☆86Updated 9 months ago