Little program written in C# to bypass EDR hooks and dump the content of the lsass process
☆60Jun 24, 2021Updated 5 years ago
Alternatives and similar repositories for LsassUnhooker
Users that are interested in LsassUnhooker are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- C# Based Universal API Unhooker☆408Feb 18, 2022Updated 4 years ago
- Manual Map Your Files, Bypass 100% Runtime.☆11Aug 31, 2022Updated 3 years ago
- A repository filled with ideas to break/detect direct syscall techniques☆26Apr 21, 2022Updated 4 years ago
- NimReflectiveLoader is a Nim-based tool for in-memory DLL execution using Reflective DLL Loading.☆31Jan 21, 2024Updated 2 years ago
- HookDetection☆45Sep 3, 2021Updated 4 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- Transparently call NTAPI via Halo's Gate with indirect syscalls.☆13Apr 26, 2024Updated 2 years ago
- C# AV/EDR Killer using less-known driver (BYOVD)☆186Nov 10, 2023Updated 2 years ago
- Terminate AV/EDR Processes using kernel driver☆355Jun 12, 2023Updated 3 years ago
- c# based port scanner with some common options to scan machines and ports. Couldf be good when stuck inside a windows internal network.☆10Apr 12, 2022Updated 4 years ago
- UAC Bypass By Abusing Kerberos Tickets☆514Aug 10, 2023Updated 2 years ago
- Hidedump:a lsassdump tools that may bypass EDR☆51May 23, 2024Updated 2 years ago
- C# code to run PIC using CreateThread☆17Apr 19, 2019Updated 7 years ago
- Lateral Movement☆126Nov 14, 2023Updated 2 years ago
- Command line & PPID spoofing☆31Apr 15, 2023Updated 3 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- 使用多种WinAPI进行权限维持的CobaltStrike脚本,包含API设置系统服务,设置计划任务,管理用户等。☆555Jan 18, 2022Updated 4 years ago
- Shellcode injection POC using syscalls.☆116Jun 5, 2020Updated 6 years ago
- Direct syscalls Injection to bypass AV/EDR☆10May 18, 2024Updated 2 years ago
- A collection of weaponized LPE exploits written in Go☆52Jan 23, 2025Updated last year
- uuid-shellcode-execution☆12May 9, 2021Updated 5 years ago
- CobaltStrike BOF - Inject ETW Bypass into Remote Process via Syscalls (HellsGate|HalosGate)☆300Sep 28, 2021Updated 4 years ago
- ☆19Dec 29, 2021Updated 4 years ago
- dump lsass进程工具☆559Jul 20, 2023Updated 3 years ago
- A Combination LSASS Dumper and LSASS Parser. All Credit goes to @slyd0g and @cube0x0.☆148Nov 21, 2021Updated 4 years ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- This is a crash for Brave Browser I found in New Years Eve, used to be a 0day when I found it☆17Feb 2, 2023Updated 3 years ago
- ☆16Feb 18, 2023Updated 3 years ago
- BloodyAv is Custom Shell Code loader to Bypass Av and Edr.☆15Mar 21, 2022Updated 4 years ago
- Tool developed using csharp (.net 4.5) for compressing and encrypting files to shorten transfer times. Supports multi-file compression an…☆14Feb 15, 2024Updated 2 years ago
- PoC module to demonstrate automated lateral movement with the Havoc C2 framework.☆313Dec 9, 2023Updated 2 years ago
- 密码收集☆57Mar 16, 2022Updated 4 years ago
- I will be uploading all the codes which I created with the help either opensource projects or blogs. This is a step by step EDR learning …☆291Aug 1, 2025Updated 11 months ago
- Using LNK files and user input simulation to start processes under explorer.exe☆34Sep 21, 2024Updated last year
- XXST-白加黑辅助挖掘工具,全程静默运行不影响正常使用☆17Apr 12, 2024Updated 2 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Inject shellcode into process via "EarlyBird"☆27Aug 30, 2021Updated 4 years ago
- A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techni…☆1,401Oct 27, 2023Updated 2 years ago
- COFF and BOF Loader written in Nim☆177Apr 4, 2026Updated 3 months ago
- Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime☆310Aug 2, 2023Updated 2 years ago
- ASPX内存执行shellcode,绕过Windows Defender(AV/EDR)☆126Dec 14, 2023Updated 2 years ago
- C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.☆112Apr 14, 2023Updated 3 years ago
- some AV / EDR / analysis studies☆10May 21, 2023Updated 3 years ago