vulnableone / BypassXLinks
The Swiss army knife of evasion tool that bypasses AMSI, Applocker, and CLM mode simultaneously.
☆27Updated last year
Alternatives and similar repositories for BypassX
Users that are interested in BypassX are comparing it to the libraries listed below
Sorting:
- Internal Monologue BOF☆74Updated 9 months ago
- Windows Thread Pool Injection Havoc Implementation☆32Updated last year
- DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.☆98Updated 2 years ago
- ☆135Updated 8 months ago
- A version of NetLoader, Execute Assemblies and Bypass ETW and AMSI using Hardware Breakpoints☆114Updated 3 months ago
- IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then refle…☆117Updated last year
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆52Updated last year
- Dynamic shellcode loader with sophisticated evasion capabilities☆192Updated 2 weeks ago
- Tools I use on red team engagements and more☆33Updated last year
- Impersonate Tokens using only NTAPI functions☆80Updated 6 months ago
- A python script that automates a C2 Profile build☆48Updated last month
- adws enumeration bof☆144Updated 2 weeks ago
- A hoontr must hoont☆99Updated 2 months ago
- Mockingjay process self injection POC☆40Updated 2 years ago
- Find DLLs with RWX section☆81Updated 2 years ago
- Lateral Movement Bof with MSI ODBC Driver Install☆125Updated 2 weeks ago
- Two in one, patch lifetime powershell console, no more etw and amsi!☆96Updated 5 months ago
- Adversary Emulation Framework☆125Updated 3 months ago
- ForsHops☆150Updated 6 months ago
- WTSImpersonator utilizes WTSQueryUserToken to steal user tokens by abusing the RPC Named Pipe "\\pipe\LSM_API_service"☆120Updated last year
- Bypass user-land hooks by syscall tampering via the Trap Flag☆127Updated last month
- Just another C2 Redirector using CloudFlare. Support multiple C2 and multiple domains. Support for websocket listener.☆175Updated 7 months ago
- Cortex EDR Ransomware protection Bypass☆25Updated 8 months ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆47Updated last year
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆84Updated last year
- a port of privkit bof for havoc☆24Updated last year
- A tool to modify SCCM remote control settings on the client machine, enabling remote control without permission prompts or notifications.…☆103Updated 11 months ago
- Evasive Payload Delivery Server & C2 Redirector☆106Updated 2 months ago
- Lateral Movement via the .NET Profiler☆84Updated 10 months ago
- Lateral Movement as loggedon User via Speech Named Pipe COM & ISpeechNamedPipe + COM Hijacking☆131Updated 3 months ago