Repository navigation

#

bypass-edr

evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)

Pascal
1450
1 年前

HookChain: A new perspective for Bypassing EDR Solutions

C
512
3 个月前

Loading BOF & ShellCode without executable permission memory.

C++
430
6 个月前

Red Team C2 Framework with AV/EDR bypass capabilities.

Python
388
6 天前

This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context of download cradle detections.

PowerShell
257
3 年前

Magical obfuscator, supports obfuscating EXE, BOF, and ShellCode.

C++
149
5 个月前

Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged

HTML
86
3 年前

Load a fresh new copy of ntdll.dll via file mapping to bypass API inline hook.

C#
60
4 年前

frida based script which automates the process of discovering and exploiting DLL Hijacks in target binaries. The discovered binaries can later be weaponized during Red Team Operations to evade AV/EDR's.

Python
51
2 年前

Efficient RAT signature locator for bypassing AV/EDR, supporting static scanning and memory scanning.

Python
38
6 个月前

PowerShell script to terminate protected processes such as anti-malware and EDRs.

PowerShell
26
2 年前

Windows 11 Syscall table. Ready to use in direct syscall. Actively maintained.

22
3 年前

Load shellcode via HELLGATE, Rewrite hellgate with .net framework for learning purpose.

C#
16
3 年前

Just an obfuscation technique in a resource file in 2 possible formats

C++
8
3 个月前

ARP Scanner, a lightweight host-alive detection tool for OPSEC.

C++
4
5 个月前
PowerShell
1
5 个月前