rad9800 / PMDLinks
☆156Updated 9 months ago
Alternatives and similar repositories for PMD
Users that are interested in PMD are comparing it to the libraries listed below
Sorting:
- This is practice VM for malware development☆179Updated 2 months ago
- ☆163Updated 7 months ago
- ☆72Updated last year
- ☆164Updated 11 months ago
- Repository containing all training and tutorials completed in preparation for the OSEE in conjunction with the AWE course.☆120Updated 3 months ago
- The different ways to dump lsass☆236Updated 5 months ago
- ZeroProbe is an advanced enumeration and analysis framework designed for exploit developers, security researchers, and red teamers. It pr…☆106Updated 10 months ago
- BSides Prishtina 2024 Malware Development and Persistence workshop☆124Updated last month
- Tools for analyzing EDR agents☆277Updated last year
- Persist like a Dodder☆67Updated 8 months ago
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆92Updated last year
- Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.☆165Updated 6 months ago
- Hide shellcode by shuffling bytes into a random array and reconstruct at runtime☆202Updated 10 months ago
- Win32 Shellcode CheatSheet: Your visual guide for crafting and understanding shellcode. Ideal for malware, and exploit developers☆66Updated last year
- RunPE implementation with multiple evasive techniques (2)☆268Updated 4 months ago
- ☆154Updated 4 months ago
- Retired TrustedSec Capabilities☆248Updated last month
- Direct access to NTFS volumes☆293Updated 5 months ago
- Evade EDR's the simple way, by not touching any of the API's they hook.☆168Updated last year
- StoneKeeper C2, an experimental EDR evasion framework for research purposes☆208Updated last year
- ☆24Updated 11 months ago
- Comprehensive Windows Syscall Extraction & Analysis Framework☆161Updated 5 months ago
- ☆189Updated 2 years ago
- Bypass user-land hooks by syscall tampering via the Trap Flag☆138Updated 5 months ago
- Python implementation of GhostPack's Seatbelt situational awareness tool☆270Updated last year
- AppLocker-Based EDR Neutralization☆289Updated last month
- collection of blogs about malware development and analysis☆63Updated 2 months ago
- Shellcode injection using the Windows Debugging API☆164Updated last month
- Scan files for potential threats while leveraging AMSI (Antimalware Scan Interface) and Windows Defender. By isolating malicious content.☆36Updated last year
- Founding is a generator that will create a loader encrypted or obfuscated with different execution types☆121Updated 5 months ago