tyranid / windows-security-internals
A repository for additional files related to the book Windows Security Internals with PowerShell from No Starch Press.
☆164Updated last year
Alternatives and similar repositories for windows-security-internals:
Users that are interested in windows-security-internals are comparing it to the libraries listed below
- A PoC of the ContainYourself research presented in DEFCON 31, which abuses the Windows containers framework to bypass EDRs.☆310Updated last year
- ☆298Updated 5 months ago
- ☆301Updated 5 months ago
- A PowerShell console in C/C++ with all the security features disabled☆228Updated last month
- Red teaming tool to dump LSASS memory, bypassing basic countermeasures.☆225Updated 3 months ago
- kernel callback removal (Bypassing EDR Detections)☆161Updated last month
- ☆105Updated 9 months ago
- Various resources to enhance Cobalt Strike's functionality and its ability to evade antivirus/EDR detection☆288Updated 11 months ago
- DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely☆357Updated 4 months ago
- An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution☆187Updated 4 months ago
- ☆178Updated last year
- Utilizing TLS callbacks to execute a payload without spawning any threads in a remote process☆257Updated last year
- I will be uploading all the codes which I created with the help either opensource projects or blogs. This is a step by step EDR learning …☆270Updated last year
- A collection of tools, scripts and personal research☆127Updated 2 weeks ago
- ☆148Updated 2 months ago
- A set of programs for analyzing common vulnerabilities in COM☆210Updated 7 months ago
- Windows rootkit designed to work with BYOVD exploits☆183Updated 3 months ago
- Find potential DLL Sideloads on your windows computer☆201Updated 3 months ago
- Kill AV/EDR leveraging BYOVD attack☆352Updated last year
- ☆186Updated last year
- Disconnected RSAT - A method of running Group Policy Manager, Certificate Authority and Certificate Templates MMC snap-ins from non-domai…☆231Updated 3 months ago
- Slides & Code snippets for a workshop held @ x33fcon 2024☆257Updated 10 months ago
- StoneKeeper C2, an experimental EDR evasion framework for research purposes☆198Updated 3 months ago
- Proof of Concept for manipulating the Kernel Callback Table in the Process Environment Block (PEB) to perform process injection and hijac…☆212Updated 5 months ago
- comprehensive .NET tool designed to extract and display detailed information about Windows Defender exclusions and Attack Surface Reducti…☆198Updated 10 months ago
- Exploitation of process killer drivers☆199Updated last year
- ☆348Updated last year
- Collect Windows telemetry for Maldev☆340Updated 2 months ago
- ShellWasp is a tool to help build shellcode that utilizes Windows syscalls, while overcoming the portability problem associated with Wind…☆166Updated last year
- Open Source C&C Specification☆243Updated last month