NTAPI hook bypass with (semi) legit stack trace
☆19May 9, 2023Updated 3 years ago
Alternatives and similar repositories for SyscallHookBypass
Users that are interested in SyscallHookBypass are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Indirect Syscall invocation via thread hijacking☆27May 5, 2023Updated 3 years ago
- An x64 binary executing code that's not inside of it.☆17Feb 28, 2023Updated 3 years ago
- EDR/AV Simulation for Malware Development☆13Oct 21, 2023Updated 2 years ago
- Rendering on external windows via hijacking thread contexts, with notes on ValidateHwnd☆14Jul 9, 2020Updated 6 years ago
- PoC arbitrary WPM without a process handle☆20Jul 22, 2023Updated 3 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Hacky code for extracting calls in DLLs by function☆16Jun 3, 2022Updated 4 years ago
- some AV / EDR / analysis studies☆10May 21, 2023Updated 3 years ago
- Transparently call NTAPI via Halo's Gate with indirect syscalls.☆13Apr 26, 2024Updated 2 years ago
- Shellcode execution via x86 inline assembly based on MSVC syntax☆17Apr 26, 2023Updated 3 years ago
- Terminate AV/EDR processes by exploiting the vulnerable NsecSoft driver☆32Sep 15, 2025Updated 11 months ago
- Inject shellcode to process using Windows NTAPI for bypassing EDRs and Antiviruses☆39Dec 9, 2020Updated 5 years ago
- A single byte modification in the kernel memory bypasses and disables all core functions of the AV/EDR security solutions☆17Aug 26, 2025Updated 11 months ago
- SamrSearch can get user info and group info with MS-SAMR.☆15Feb 15, 2022Updated 4 years ago
- ☆19Feb 23, 2023Updated 3 years ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Splitting and executing shellcode across multiple pages☆103Jun 8, 2023Updated 3 years ago
- Win64 UEFI Driver-based tool for unrestricted memory R/W☆31Feb 8, 2022Updated 4 years ago
- BloodyAv is Custom Shell Code loader to Bypass Av and Edr.☆15Mar 21, 2022Updated 4 years ago
- Simple Windows shellcode loader with interesting evasion tricks☆15Apr 27, 2025Updated last year
- Memory hacking library powered by AMD SVM☆24Mar 16, 2023Updated 3 years ago
- ☆75Dec 19, 2024Updated last year
- 64bit WIndows 10 shellcode dat pops dat calc - Dynamic & Null Free☆65Mar 8, 2023Updated 3 years ago
- This code example allows you to create a malware.exe sample that can be run in the context of a system service, and could be used for loc…☆55May 8, 2023Updated 3 years ago
- Instrumenting a binary without source code to bypass anti-debug checks☆40Sep 25, 2021Updated 4 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- (WIP) A Recursive UDRL leveraging smelly_vx's Feverdream trick.☆19Sep 3, 2025Updated 11 months ago
- MSBuild AL bypass☆16Mar 9, 2023Updated 3 years ago
- A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge …☆34Mar 20, 2023Updated 3 years ago
- Helper script for identifying bad characters based on (Immunity|edb)'s stack dump☆13Mar 18, 2023Updated 3 years ago
- Use hardware breakpoints to spoof the call stack for both syscalls and API calls☆206Jun 6, 2024Updated 2 years ago
- A Dropper POC with a focus on aiding in EDR evasion, NTDLL Unhooking followed by loading ntdll in-memory, which is present as shellcode (…☆178Feb 10, 2023Updated 3 years ago
- ☆13Feb 25, 2023Updated 3 years ago
- PINTool to help analyzing malware that uses process injection☆16Jan 3, 2022Updated 4 years ago
- C# Based Universal API Unhooker - Automatically Unhook API Hives (ntdll.dll,kernel32.dll,user32.dll,and kernelbase.dll)☆24Mar 7, 2023Updated 3 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- This project is an EDRSandblast fork, adding some features and custom pieces of code.☆16Jan 10, 2024Updated 2 years ago
- Bypassing AV, EDR, Application Whitelisting and ASR Rules☆13Apr 18, 2023Updated 3 years ago
- Attempts to suspend all known AV/EDRs processes on Windows using syscalls and the undocumented NtSuspendProcess API. Made with <3 for pen…☆12May 11, 2023Updated 3 years ago
- PoC code for IsValidImageCRC()☆25May 3, 2023Updated 3 years ago
- ASM Bootkit that patches DSE at boot allowing to load unsigned drivers☆19Aug 24, 2025Updated 11 months ago
- UEFI Bootkit that infects kernel with backdoor using SSDT hook☆28Jul 9, 2025Updated last year
- Collection of UAC Bypass Techniques Weaponized as BOFs☆22Jan 5, 2026Updated 7 months ago