tyranid / windows-security-internalsLinks
A repository for additional files related to the book Windows Security Internals with PowerShell from No Starch Press.
☆204Updated 3 weeks ago
Alternatives and similar repositories for windows-security-internals
Users that are interested in windows-security-internals are comparing it to the libraries listed below
Sorting:
- A PoC of the ContainYourself research presented in DEFCON 31, which abuses the Windows containers framework to bypass EDRs.☆317Updated 2 years ago
- ☆324Updated this week
- Gain insights into MS-RPC implementations that may be vulnerable using an automated approach and make it easy to visualize the data. By f…☆291Updated 2 weeks ago
- POC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY☆205Updated 5 months ago
- Tools for analyzing EDR agents☆249Updated last year
- Exploring RPC interfaces on Windows☆330Updated last year
- Open Source C&C Specification☆267Updated 6 months ago
- ☆300Updated 10 months ago
- A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.☆355Updated 7 months ago
- Collect Windows telemetry for Maldev☆419Updated last week
- Slides & Code snippets for a workshop held @ x33fcon 2024☆268Updated last year
- AV/EDR Lab environment setup references to help in Malware development☆401Updated 6 months ago
- A small program written in C that is designed to load 32/64-bit shellcode and allow for execution or debugging. Can also output PE files …☆160Updated last year
- Proof of concept & details for CVE-2025-21298☆189Updated 7 months ago
- A PowerShell console in C/C++ with all the security features disabled☆271Updated 3 months ago
- .net config loader☆339Updated last year
- I will be uploading all the codes which I created with the help either opensource projects or blogs. This is a step by step EDR learning …☆283Updated last month
- ☆284Updated 3 weeks ago
- DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely☆379Updated 9 months ago
- Proof of Concept (PoC) .NET tool for remotely killing EDR with WDAC☆378Updated 8 months ago
- ☆105Updated last year
- EDRSandblast-GodFault☆266Updated 2 years ago
- ☆234Updated 2 years ago
- kernel callback removal (Bypassing EDR Detections)☆188Updated 5 months ago
- Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry☆433Updated last year
- Various resources to enhance Cobalt Strike's functionality and its ability to evade antivirus/EDR detection☆309Updated last year
- Simulate the behavior of AV/EDR for malware development training.☆539Updated last year
- ☆260Updated last year
- ☆553Updated last year
- A new technique that can be used to bypass memory scanners. This can be useful in hiding problematic code (such as reflective loaders imp…☆329Updated 11 months ago