Repository navigation

#

bypass-edr

evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)

Pascal
1489
2 年前

HookChain: A new perspective for Bypassing EDR Solutions

C
566
9 个月前

Loading BOF & ShellCode without executable permission memory.

C++
435
1 年前

Red Team C2 Framework with AV/EDR bypass capabilities.

Python
407
6 个月前

This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context of download cradle detections.

PowerShell
257
3 年前

Magical obfuscator, supports obfuscating EXE, BOF, and ShellCode.

C++
153
10 个月前

Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged

HTML
87
3 年前

Load a fresh new copy of ntdll.dll via file mapping to bypass API inline hook.

C#
62
4 年前

frida based script which automates the process of discovering and exploiting DLL Hijacks in target binaries. The discovered binaries can later be weaponized during Red Team Operations to evade AV/EDR's.

Python
53
2 年前

Efficient RAT signature locator for bypassing AV/EDR, supporting static scanning and memory scanning.

Python
43
1 年前

PowerShell script to terminate protected processes such as anti-malware and EDRs.

PowerShell
28
2 年前

Windows 11 Syscall table. Ready to use in direct syscall. Actively maintained.

23
4 年前

Load shellcode via HELLGATE, Rewrite hellgate with .net framework for learning purpose.

C#
16
4 年前

Just an obfuscation technique in a resource file in 2 possible formats

C++
9
12 天前

ARP Scanner, a lightweight host-alive detection tool for OPSEC.

C++
4
1 年前
PowerShell
1
10 个月前