reveng007 / Learning-EDR-and-EDR_Evasion
I will be uploading all the codes which I created with the help either opensource projects or blogs. This is a step by step EDR learning path for me.
☆271Updated last year
Alternatives and similar repositories for Learning-EDR-and-EDR_Evasion:
Users that are interested in Learning-EDR-and-EDR_Evasion are comparing it to the libraries listed below
- Various resources to enhance Cobalt Strike's functionality and its ability to evade antivirus/EDR detection☆280Updated 10 months ago
- AV/EDR Lab environment setup references to help in Malware development☆369Updated last month
- Kill AV/EDR leveraging BYOVD attack☆343Updated last year
- Materials for the workshop "Red Team Ops: Havoc 101"☆367Updated 5 months ago
- Amsi Bypass payload that works on Windwos 11☆376Updated last year
- ☆342Updated last year
- C# AV/EDR Killer using less-known driver (BYOVD)☆172Updated last year
- ☆274Updated last year
- Simulate the behavior of AV/EDR for malware development training.☆514Updated last year
- This comprehensive process injection series is crafted for cybersecurity enthusiasts, researchers, and professionals who aim to stay at t…☆367Updated 3 months ago
- Open Source C&C Specification☆240Updated 3 weeks ago
- .NET post-exploitation toolkit for Active Directory reconnaissance and exploitation☆276Updated 4 months ago
- Collection of OPSEC Tradecraft and TTPs for Red Team Operations☆287Updated last month
- PoC module to demonstrate automated lateral movement with the Havoc C2 framework.☆289Updated last year
- PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.☆395Updated 9 months ago
- Slides & Code snippets for a workshop held @ x33fcon 2024☆255Updated 9 months ago
- Protected Process Dumper Tool☆532Updated last year
- "AMSI WRITE RAID" Vulnerability that leads to an effective AMSI BYPASS☆255Updated this week
- Proof of Concept (PoC) .NET tool for remotely killing EDR with WDAC☆343Updated 2 months ago
- ☆349Updated 3 months ago
- comprehensive .NET tool designed to extract and display detailed information about Windows Defender exclusions and Attack Surface Reducti…☆195Updated 9 months ago
- Find potential DLL Sideloads on your windows computer☆176Updated 2 months ago
- Analyse your malware to surgically obfuscate it☆454Updated 3 weeks ago
- ☆254Updated last year
- Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8☆350Updated 6 months ago
- Python implementation of GhostPack's Seatbelt situational awareness tool☆255Updated 4 months ago
- 「💀」Proof of concept on BYOVD attack☆155Updated 3 months ago
- Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry☆394Updated 7 months ago
- GregsBestFriend process injection code created from the White Knight Labs Offensive Development course☆184Updated last year