ytincodenito / vEDRLinks
Vulnerable EDR
☆16Updated 6 months ago
Alternatives and similar repositories for vEDR
Users that are interested in vEDR are comparing it to the libraries listed below
Sorting:
- Safely manage the unloading of DLLs that have been hooked into a process. Context: https://github.com/KNSoft/KNSoft.SlimDetours/discussio…☆76Updated last month
- A fast method to intercept syscalls from any user-mode process using InstrumentationCallback and detect any process using Instrumentation…☆31Updated last year
- Get-PDInvokeImports is tool (PowerShell module) which is able to perform automatic detection of P/Invoke, Dynamic P/Invoke and D/Invoke u…☆54Updated 3 years ago
- Monitors ETW for security relevant syscalls maintaining the set called by each unique process☆79Updated 2 years ago
- EDR/AV Simulation for Malware Development☆13Updated last year
- Titan: A crappy Reflective Loader written in C and assembly for Cobalt Strike. Redirects DNS Beacon over DoH☆48Updated 3 years ago
- ☆25Updated 2 years ago
- Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules☆78Updated this week
- Uses ghidra to find all ETW write metadata for each API in a PE file☆19Updated 10 months ago
- Process Injection: APC Injection☆32Updated 4 years ago
- https://github.com/janoglezcampos/c_syscalls with the ASM rewritten by myself for Visual Studio's Compiler.☆31Updated 11 months ago
- ☆40Updated 3 months ago
- Standalone Metasploit-like XOR encoder for shellcode☆47Updated last year
- ☆31Updated 3 months ago
- Unpacker for donut shellcode☆17Updated 4 years ago
- A Practical example of ELAM (Early Launch Anti-Malware)☆33Updated 3 years ago
- Small tool to play with IOCs caused by Imageload events☆42Updated 2 years ago
- Exploiting the KsecDD Windows driver through Server Silos☆71Updated 6 months ago
- ☆52Updated 7 months ago
- ☆113Updated 2 years ago
- Detours implementation (x64/x86) which used only ntdll import☆90Updated 11 months ago
- The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent …☆39Updated 2 years ago
- ☆115Updated 2 years ago
- yet another sleep encryption thing. also used the default github repo name for this one.☆69Updated 2 years ago
- ☆84Updated last year
- Read ETW Provider events. Inspired by ETWExplorer by Pavel Yosifovich☆16Updated 11 months ago
- Enabled / Disable LSA Protection via BYOVD☆68Updated 3 years ago
- Herpaderply Hollowing - a PE injection technique, hybrid between Process Hollowing and Process Herpaderping☆56Updated 2 years ago
- havoc kaine plugin to mitigate PAGE_GUARD protected image headers using JOP gadgets☆30Updated 10 months ago
- Fork of Get-InjectedThread - https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2☆41Updated last year