rad9800 / FileRenameJunctionsEDRDisable
☆154Updated 5 months ago
Alternatives and similar repositories for FileRenameJunctionsEDRDisable
Users that are interested in FileRenameJunctionsEDRDisable are comparing it to the libraries listed below
Sorting:
- Injecting DLL into LSASS at boot☆94Updated 2 weeks ago
- ☆106Updated 3 months ago
- ☆154Updated 9 months ago
- ☆114Updated 2 months ago
- ☆109Updated 3 months ago
- Two in one, patch lifetime powershell console, no more etw and amsi!☆88Updated 2 weeks ago
- Shellcode loader☆81Updated 5 months ago
- Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.☆93Updated this week
- ☆128Updated 3 months ago
- Port of Cobalt Strike's Process Inject Kit☆175Updated 5 months ago
- Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination…☆141Updated 9 months ago
- TypeLib persistence technique☆115Updated 6 months ago
- Construct the payload at runtime using an array of offsets☆63Updated 10 months ago
- An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution☆187Updated 5 months ago
- ☆151Updated last year
- Stage 0☆159Updated 4 months ago
- A variation of ProcessOverwriting to execute shellcode on an executable's section☆148Updated last year
- Bypass LSA protection using the BYODLL technique☆158Updated 7 months ago
- A Mythic agent for Windows written in C☆121Updated 3 weeks ago
- ☆106Updated last month
- Ghosting-AMSI☆165Updated 2 weeks ago
- ☆184Updated last year
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆74Updated 9 months ago
- A Mythic Agent written in PIC C.☆189Updated 3 months ago
- "Service-less" driver loading☆154Updated 5 months ago
- ForsHops☆131Updated last month
- Adversary Emulation Framework☆98Updated 9 months ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆46Updated last year
- Cobaltstrike Reflective Loader with Synthetic Stackframe☆118Updated 3 months ago
- A Powershell AMSI Bypass technique via Vectored Exception Handler (VEH). This technique does not perform assembly instruction patching, f…☆160Updated 11 months ago