volexity / donut-decryptorLinks
Retrieve inner payloads from Donut samples
☆112Updated last week
Alternatives and similar repositories for donut-decryptor
Users that are interested in donut-decryptor are comparing it to the libraries listed below
Sorting:
- Windows Persistence IT-Security☆108Updated 9 months ago
- Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules☆134Updated this week
- ETW based POC to identify direct and indirect syscalls☆190Updated 2 years ago
- Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination…☆139Updated last year
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆105Updated last year
- IoctlHunter is a command-line tool designed to simplify the analysis of IOCTL calls made by userland software targeting Windows drivers.☆104Updated last year
- Detect EDR's exceptions by inspecting processes' loaded modules☆130Updated last year
- ☆159Updated 11 months ago
- Evasion Escaper is a project aimed at evading the checks that malicious software performs to detect if it's running in a virtual environm…☆110Updated 10 months ago
- ☆88Updated 2 years ago
- This repo will contain the core detection, only for Cobaltstrike's leaked versions. Non-leaked version detections wont be shared☆90Updated 2 years ago
- ☆120Updated last year
- A small program written in C that is designed to load 32/64-bit shellcode and allow for execution or debugging. Can also output PE files …☆167Updated last year
- Finding secrets in kernel and user memory☆116Updated 2 years ago
- A collection of tools and detections for the Sliver C2 Frameworj☆133Updated 2 years ago
- A PoC of the ContainYourself research presented in DEFCON 31, which abuses the Windows containers framework to bypass EDRs.☆316Updated 2 years ago
- StoneKeeper C2, an experimental EDR evasion framework for research purposes☆207Updated 11 months ago
- A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.☆251Updated 2 months ago
- Two tools written in C that block network traffic for blacklisted EDR processes, using either Windows Defender Firewall (WDF) or Windows …☆251Updated 2 months ago
- Version 2 - A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders …☆102Updated 8 months ago
- Embedder is a collection of sources in different languages to embed Python interpreter with minimal dependencies☆121Updated last year
- Blog/Journal on how to backdoor VSCode extensions☆75Updated 4 months ago
- ☆80Updated last year
- ☆105Updated last year
- Tools for analyzing EDR agents☆271Updated last year
- .NET tool used to enrich RPC telemetry☆100Updated 5 months ago
- I have documented all of the AMSI patches that I learned till now☆76Updated last month
- Local & remote Windows DLL Proxying☆169Updated last year
- ☆64Updated last year
- GoResolver is a Go analysis tool using both Go symbol extraction and Control Flow Graph (CFG) similarity to identify and resolve the func…☆75Updated 3 months ago