yutianqaq / x1LdrLinks
XOR 加密 分离免杀
☆67Updated last year
Alternatives and similar repositories for x1Ldr
Users that are interested in x1Ldr are comparing it to the libraries listed below
Sorting:
- 一个2020年练手的基于gin框架搞的在线免杀平台,支持后台管理,邀请码注册等☆38Updated 11 months ago
- Red team tool designed for quickly identifying hijackable programs, evading antivirus software, and EDR (Endpoint Detection and Response)…☆73Updated 5 months ago
- 通过C/C++实现的 Windows RID Hijacking persistence technique (RID劫持 影子账户 账户克隆).☆83Updated 3 years ago
- ☆35Updated 2 years ago
- 免杀计划任务进行权限维持,过主流杀软。 A schtask tool bypass anti-virus☆68Updated 2 years ago
- 一种通过进程注入实现强制关闭部分杀软进程的方法(以360安全卫士和360杀毒为例)☆137Updated last year
- 主要用于隐藏进程真实路径,进程带windows真签名☆114Updated 10 months ago
- Hidedump:a lsassdump tools that may bypass EDR☆51Updated last year
- Loader Pre-Technology, Main thread hijacking without using API, get ntdll and kernel32 handle without peb. 加载器前置技术,不使用API进行主线程劫持,不使用PEB…☆80Updated 3 weeks ago
- dll劫持、dll hijack、Bypass Antivirus、Red Team☆50Updated 9 months ago
- 利用EFSRPC协议批量探测出网☆66Updated last year
- This is a third party agent for Havoc C2 written in golang.☆58Updated last year
- Get password/cookie/history from browser and use devtools protocol to bypass edr monitoring☆62Updated 4 months ago
- 用于解密并加载shellcode,支持RC4和AES两种解密方法,并使用DInvoke来动态调用WinAPI函数,从而尝试绕过某些安全解决方案☆31Updated last year
- ☆46Updated 8 months ago
- File entropy calculator - Golang☆28Updated last year
- ☆49Updated 2 years ago
- 重构Beacon☆15Updated 11 months ago
- go实现的shellcode免杀加载器,实测时可过火绒,360。当前效果请自行评判。☆40Updated 11 months ago
- 用c#实现了个远程拉取Mimikatz.ps1☆61Updated last year
- 重构Beacon☆160Updated last year
- 制作 shellcode 的模板☆27Updated 9 months ago
- kill windows log☆45Updated last year
- 过木马免杀制作器☆55Updated last year
- 集成了截图 键盘记录 剪贴版功能,用于网络限制场景下的信息搜集☆85Updated last year
- Delete file regardless of whether the handle is used via SetFileInformationByHandle☆49Updated 2 years ago
- Shellcode Reductio Entropy Tools☆71Updated last year
- bypass edr杀软的dumplsass工具☆19Updated 5 months ago
- BOF implementation of delete self poc that delete a locked executable or a currently running file from disk by its pid, path, or the curr…☆78Updated 2 years ago
- 魔改shadowsocks,实现socks5内网穿透。☆62Updated last year