Little program written in C# to bypass EDR hooks and dump the content of the lsass process
☆59Jun 24, 2021Updated 5 years ago
Alternatives and similar repositories for LsassUnhooker
Users that are interested in LsassUnhooker are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- C# Based Universal API Unhooker☆408Feb 18, 2022Updated 4 years ago
- Manual Map Your Files, Bypass 100% Runtime.☆11Aug 31, 2022Updated 4 years ago
- A repository filled with ideas to break/detect direct syscall techniques☆25Apr 21, 2022Updated 4 years ago
- NimReflectiveLoader is a Nim-based tool for in-memory DLL execution using Reflective DLL Loading.☆32Jan 21, 2024Updated 2 years ago
- HookDetection☆43Sep 3, 2021Updated 5 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Transparently call NTAPI via Halo's Gate with indirect syscalls.☆13Apr 26, 2024Updated 2 years ago
- C# AV/EDR Killer using less-known driver (BYOVD)☆188Nov 10, 2023Updated 2 years ago
- Terminate AV/EDR Processes using kernel driver☆351Jun 12, 2023Updated 3 years ago
- c# based port scanner with some common options to scan machines and ports. Couldf be good when stuck inside a windows internal network.☆10Apr 12, 2022Updated 4 years ago
- Socks proxy server using powershell. Supports local and reverse connections for pivoting.☆10Oct 7, 2020Updated 6 years ago
- UAC Bypass By Abusing Kerberos Tickets☆511Aug 10, 2023Updated 3 years ago
- Hidedump:a lsassdump tools that may bypass EDR☆51May 23, 2024Updated 2 years ago
- Lateral Movement☆125Nov 14, 2023Updated 2 years ago
- Command line & PPID spoofing☆31Apr 15, 2023Updated 3 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- 使用多种WinAPI进行权限维持的CobaltStrike脚本,包含API设置系统服务,设置计划任务,管理用户等。☆551Jan 18, 2022Updated 4 years ago
- Shellcode injection POC using syscalls.☆116Jun 5, 2020Updated 6 years ago
- Using LNK files and user input simulation to start processes under explorer.exe☆32Sep 21, 2024Updated 2 years ago
- Direct syscalls Injection to bypass AV/EDR☆10May 18, 2024Updated 2 years ago
- A collection of weaponized LPE exploits written in Go☆52Jan 23, 2025Updated last year
- uuid-shellcode-execution☆12May 9, 2021Updated 5 years ago
- CobaltStrike BOF - Inject ETW Bypass into Remote Process via Syscalls (HellsGate|HalosGate)☆298Sep 28, 2021Updated 5 years ago
- ☆20Dec 29, 2021Updated 4 years ago
- dump lsass进程工具☆556Jul 20, 2023Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A Combination LSASS Dumper and LSASS Parser. All Credit goes to @slyd0g and @cube0x0.☆147Nov 21, 2021Updated 4 years ago
- This is a crash for Brave Browser I found in New Years Eve, used to be a 0day when I found it☆17Feb 2, 2023Updated 3 years ago
- ☆16Feb 18, 2023Updated 3 years ago
- BloodyAv is Custom Shell Code loader to Bypass Av and Edr.☆15Mar 21, 2022Updated 4 years ago
- Tool developed using csharp (.net 4.5) for compressing and encrypting files to shorten transfer times. Supports multi-file compression an…☆13Feb 15, 2024Updated 2 years ago
- 密码收集☆57Mar 16, 2022Updated 4 years ago
- PoC module to demonstrate automated lateral movement with the Havoc C2 framework.☆311Dec 9, 2023Updated 2 years ago
- I will be uploading all the codes which I created with the help either opensource projects or blogs. This is a step by step EDR learning …☆292Aug 1, 2025Updated last year
- Inject shellcode into process via "EarlyBird"☆27Aug 30, 2021Updated 5 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- XXST-白加黑辅助挖掘工具,全程静默运行不影响正常使用☆17Apr 12, 2024Updated 2 years ago
- A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techni…☆1,419Oct 27, 2023Updated 2 years ago
- COFF and BOF Loader written in Nim☆178Apr 4, 2026Updated 6 months ago
- Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime☆305Aug 2, 2023Updated 3 years ago
- ASPX内存执行shellcode,绕过Windows Defender(AV/EDR)☆123Dec 14, 2023Updated 2 years ago
- C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.☆112Apr 14, 2023Updated 3 years ago
- some AV / EDR / analysis studies☆10May 21, 2023Updated 3 years ago