Workshop materials for “Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel” presented at DEF CON 34 and BSidesLV 2026. Covers malware development, EDR Architecture, EDR evasion, C2 customization, and kernel-level techniques.
☆387Aug 16, 2026Updated last month
Alternatives and similar repositories for edrEvasionWorkshop
Users that are interested in edrEvasionWorkshop are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.☆90Jun 15, 2026Updated 3 months ago
- Demonstrate how a signed driver can bypass defenses to deploy ransomware on Windows 11 with advanced AV and UAC evasion techniques.☆34Updated this week
- ☆70Jul 12, 2026Updated 2 months ago
- Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advance…☆118Sep 17, 2026Updated last week
- Windows native ETW inspection suite for browsing providers, reading metadata, consuming live events, recording ETL traces, filtering resu…☆112Jul 27, 2026Updated 2 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A cmake template for crystal palace☆48Dec 20, 2025Updated 9 months ago
- Novel Windows process injection: assembles existing open handles (process & thread), natural RWX regions, and special user APC (NtQueueAp…☆74Feb 17, 2026Updated 7 months ago
- A cross-platform, collaborative C2 for red-teaming. Agents are cross-compilable (e.g, you can generate Windows DLLs on Linux), cross-comp…☆23Mar 7, 2025Updated last year
- 一个各类漏洞POC知识库☆10Jul 17, 2023Updated 3 years ago
- NimSkrull is an adaption from the original Skrull malware anti-copy DRM. Only for the anti-copy feature. (https://github.com/aaaddress1/S…☆13May 20, 2023Updated 3 years ago
- The code is a pingback to the Dark Vortex blog: https://0xdarkvortex.dev/hiding-memory-allocations-from-mdatp-etwti-stack-tracing/☆218Jan 29, 2023Updated 3 years ago
- Crystal Palace Evasion kit for Sliver☆118Jun 13, 2026Updated 3 months ago
- Windows User-Mode Shellcode Development Framework (WUMSDF)☆159Jul 15, 2026Updated 2 months ago
- ☆38Mar 31, 2025Updated last year
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Easy to use, open-source infrastructure management platform, crafted specifically for red team engagements.☆111Jul 17, 2026Updated 2 months ago
- PowerShell tool to deploy deceptive Active Directory objects, and audit them☆16Jan 7, 2026Updated 8 months ago
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆51Jul 23, 2026Updated 2 months ago
- ☆40Feb 26, 2025Updated last year
- Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.☆222Jan 6, 2026Updated 8 months ago
- The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencie…☆183Sep 3, 2025Updated last year
- LibPicoManager is a unified PICO management framework that provides centralized control over PICOs in memory, enabling dynamic code loadi…☆42Dec 1, 2025Updated 9 months ago
- Proof of concept to detect module stomping detection by looking for modified .pdata sections.☆41Jun 11, 2026Updated 3 months ago
- Proof-of-concept implementation of AI-enabled postex DLLs☆98Sep 10, 2025Updated last year
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- A service container for interacting with SRA's VECTR☆18Apr 9, 2025Updated last year
- A Windows x64 offensive research framework that constructs fully synthetic call stacks☆72Jul 14, 2026Updated 2 months ago
- LibIPC is a simple Crystal Palace shared library for inter-process communication, based on Named Pipes.☆27Nov 4, 2025Updated 10 months ago
- sigreturn-oriented(SROP) based sleep obfuscation poc for Linux☆68Dec 15, 2025Updated 9 months ago
- A synergized Visual Studio and Rust development environment☆17Jan 25, 2025Updated last year
- Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.☆422Sep 3, 2026Updated 3 weeks ago
- A lightweight test harness designed to speed up shellcode development by providing an execution environment with integrated crash diagnos…☆45Jan 15, 2026Updated 8 months ago
- Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.☆23Nov 11, 2025Updated 10 months ago
- GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumera…☆44Aug 9, 2026Updated last month
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- BOF POC of the DSCourier project / invoking WinGet via COM☆90Apr 23, 2026Updated 5 months ago
- User-mode ETW interception and telemetry manipulation lab for Windows security research.☆44Jun 15, 2026Updated 3 months ago
- PICO-Implant is a Proof of Concept C2 implant built using Position-independent Code Objects (PICO) for modular functionality. This projec…☆56Nov 9, 2025Updated 10 months ago
- Brute Ratel External C2 (Microsoft Teams)☆38Dec 11, 2024Updated last year
- ☆15Feb 20, 2026Updated 7 months ago
- Parses cached certificate templates from a Windows Registry file and displays them in the same style as Certipy does☆97Jul 3, 2025Updated last year
- a windows-ir skill☆34Sep 6, 2026Updated 3 weeks ago