Workshop materials for “Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel” presented at DEF CON 34 and BSidesLV 2026. Covers malware development, EDR Architecture, EDR evasion, C2 customization, and kernel-level techniques.
☆330Aug 16, 2026Updated 3 weeks ago
Alternatives and similar repositories for edrEvasionWorkshop
Users that are interested in edrEvasionWorkshop are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.☆89Jun 15, 2026Updated 2 months ago
- ☆66Jul 12, 2026Updated last month
- Demonstrate how a signed driver can bypass defenses to deploy ransomware on Windows 11 with advanced AV and UAC evasion techniques.☆34Updated this week
- Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advance…☆117Jun 30, 2026Updated 2 months ago
- Windows native ETW inspection suite for browsing providers, reading metadata, consuming live events, recording ETL traces, filtering resu…☆111Jul 27, 2026Updated last month
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A cmake template for crystal palace☆48Dec 20, 2025Updated 8 months ago
- Novel Windows process injection: assembles existing open handles (process & thread), natural RWX regions, and special user APC (NtQueueAp…☆75Feb 17, 2026Updated 6 months ago
- A cross-platform, collaborative C2 for red-teaming. Agents are cross-compilable (e.g, you can generate Windows DLLs on Linux), cross-comp…☆23Mar 7, 2025Updated last year
- 一个各类漏洞POC知识库☆10Jul 17, 2023Updated 3 years ago
- NimSkrull is an adaption from the original Skrull malware anti-copy DRM. Only for the anti-copy feature. (https://github.com/aaaddress1/S…☆13May 20, 2023Updated 3 years ago
- A QoL tool to obfuscate shellcode.☆28Jun 2, 2026Updated 3 months ago
- The code is a pingback to the Dark Vortex blog: https://0xdarkvortex.dev/hiding-memory-allocations-from-mdatp-etwti-stack-tracing/☆218Jan 29, 2023Updated 3 years ago
- Crystal Palace Evasion kit for Sliver☆114Jun 13, 2026Updated 2 months ago
- Windows User-Mode Shellcode Development Framework (WUMSDF)☆158Jul 15, 2026Updated last month
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- ☆38Mar 31, 2025Updated last year
- Easy to use, open-source infrastructure management platform, crafted specifically for red team engagements.☆109Jul 17, 2026Updated last month
- PowerShell tool to deploy deceptive Active Directory objects, and audit them☆16Jan 7, 2026Updated 8 months ago
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆50Jul 23, 2026Updated last month
- ☆41Feb 26, 2025Updated last year
- Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.☆224Jan 6, 2026Updated 8 months ago
- The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencie…☆183Sep 3, 2025Updated last year
- LibPicoManager is a unified PICO management framework that provides centralized control over PICOs in memory, enabling dynamic code loadi…☆43Dec 1, 2025Updated 9 months ago
- Proof of concept to detect module stomping detection by looking for modified .pdata sections.☆41Jun 11, 2026Updated 2 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Proof-of-concept implementation of AI-enabled postex DLLs☆97Sep 10, 2025Updated 11 months ago
- A service container for interacting with SRA's VECTR☆18Apr 9, 2025Updated last year
- A Windows x64 offensive research framework that constructs fully synthetic call stacks☆70Jul 14, 2026Updated last month
- LibIPC is a simple Crystal Palace shared library for inter-process communication, based on Named Pipes.☆29Nov 4, 2025Updated 10 months ago
- sigreturn-oriented(SROP) based sleep obfuscation poc for Linux☆69Dec 15, 2025Updated 8 months ago
- A synergized Visual Studio and Rust development environment☆19Jan 25, 2025Updated last year
- Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.☆421Updated this week
- A lightweight test harness designed to speed up shellcode development by providing an execution environment with integrated crash diagnos…☆46Jan 15, 2026Updated 7 months ago
- Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.☆23Nov 11, 2025Updated 9 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- BOF POC of the DSCourier project / invoking WinGet via COM☆90Apr 23, 2026Updated 4 months ago
- GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumera…☆44Aug 9, 2026Updated 3 weeks ago
- PICO-Implant is a Proof of Concept C2 implant built using Position-independent Code Objects (PICO) for modular functionality. This projec…☆57Nov 9, 2025Updated 9 months ago
- User-mode ETW interception and telemetry manipulation lab for Windows security research.☆44Jun 15, 2026Updated 2 months ago
- Brute Ratel External C2 (Microsoft Teams)☆38Dec 11, 2024Updated last year
- ☆15Feb 20, 2026Updated 6 months ago
- Parses cached certificate templates from a Windows Registry file and displays them in the same style as Certipy does☆96Jul 3, 2025Updated last year