Extracted Yara rules from Windows Defender mpavbase and mpasbase
☆541May 14, 2026Updated 3 months ago
Alternatives and similar repositories for DefenderYara
Users that are interested in DefenderYara are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules☆219Updated this week
- Cobalt Strike UDRL for memory scanner evasion.☆1,031Jun 4, 2024Updated 2 years ago
- Elastic Security detection content for Endpoint☆1,486Updated this week
- A BOF that runs unmanaged PEs inline☆702Oct 23, 2024Updated last year
- Stack Spoofing with Synthetic frames based on the work of namazso, SilentMoonWalk, and VulcanRaven☆270Oct 16, 2024Updated last year
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Collect Windows telemetry for Maldev☆505Aug 14, 2026Updated 2 weeks ago
- DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely☆396Dec 13, 2024Updated last year
- A beacon object file implementation of PoolParty Process Injection Technique.☆458Dec 21, 2023Updated 2 years ago
- ROP-based sleep obfuscation to evade memory scanners☆392Jun 22, 2025Updated last year
- Reverse engineering winapi function loadlibrary.☆253Apr 17, 2023Updated 3 years ago
- Two new offensive techniques using Windows Fibers: PoisonFiber (The first remote enumeration & Fiber injection capability POC tool) Phan…☆286Sep 18, 2024Updated last year
- An example reference design for a proposed BOF PE☆245Jan 23, 2026Updated 7 months ago
- Process Injection using Thread Name☆312Apr 18, 2025Updated last year
- For when DLLMain is the only way☆437Oct 29, 2024Updated last year
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the …☆1,899Nov 3, 2024Updated last year
- Because AV evasion should be easy.☆901Nov 28, 2024Updated last year
- ☆1,846Aug 30, 2024Updated 2 years ago
- A modern 32/64-bit position independent implant template