Lists (1)
Sort Name ascending (A-Z)
Stars
Stable powershell Obfuscator with lots of room for improvement
Most advanced and poorly coded windows batch obfuscator ever made (aka the best)
Two in one, patch lifetime powershell console, no more etw and amsi!
Next-Gen Stealer written in Go. Stealing from Discord, Chromium-Based & Firefox-Based Browsers, Crypto Wallets and more, from every user on every disk. (PoC. For educational purposes only)
SecDbg / ThunderKitty
Forked from EvilBytecode/ThunderKitty🔑 Open source stealer written in Go, all logs will be sent to Telegram bot.
Y0ung-DST / awesome-forensics
Forked from cugu/awesome-forensicsA curated list of awesome forensic analysis tools and resources
kill anti-malware protected processes ( BYOVD) ( Microsoft Won)
Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes
Discord RAT: A versatile bot-based C2 tool that can manage multiple clients at once.
A small POC to make defender useless by removing its token privileges and lowering the token integrity
Proof of Concept example for abusing Process Hacker 2 (v2.39.124)
🦫 | GoRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team, with a specific focus on the Go programming language, all is made for educati…
Null-AMSI is an AMSI and ETW bypass that takes advantage of .NET types (.NET Reflection) to bypassing AV/EDR.
Purpleteam scripts simulation & Detection - trigger events for SOC detections
yara detection rules for hunting with the threathunting-keywords project
An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer
Identify common EDR processes, directories, and services. Simple BOF of Invoke-EDRChecker.
Reproducing Spyboy technique, which involves terminating all EDR/XDR/AVs processes by abusing the zam64.sys driver
Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry
A basic Python API client for MITRE Caldera
Simulation environment for attacks on computer networks
Detect WFP filters blocking EDR communications
AutoGPT is the vision of accessible AI for everyone, to use and to build on. Our mission is to provide the tools, so that you can focus on what matters.
A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.