bypass-edr
Here are 21 public repositories matching this topic...
Sort:Most stars
evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)
- Updated
Dec 21, 2023 - Pascal
HookChain: A new perspective for Bypassing EDR Solutions
- Updated
Jan 5, 2025 - C
Loading BOF & ShellCode without executable permission memory.
- Updated
Oct 23, 2024 - C++
Red Team C2 Framework with AV/EDR bypass capabilities.
- Updated
Feb 12, 2025 - Python
This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context of download cradle detections.
- Updated
Jul 7, 2022 - PowerShell
Magical obfuscator, supports obfuscating EXE, BOF, and ShellCode.
- Updated
Nov 25, 2024 - C++
Evasive Golang Loader
- Updated
Jul 27, 2024 - Go
Generate DLL Hijacking Payload in batches.
- Updated
Aug 15, 2024 - Python
Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged
- Updated
Jul 7, 2022 - HTML
Load a fresh new copy of ntdll.dll via file mapping to bypass API inline hook.
- Updated
Sep 6, 2021 - C#
frida based script which automates the process of discovering and exploiting DLL Hijacks in target binaries. The discovered binaries can later be weaponized during Red Team Operations to evade AV/EDR's.
- Updated
Apr 18, 2023 - Python
Rust malware EDR evasion via direct syscalls, fully implemented as an example in Rust
- Updated
Jun 4, 2024 - Rust
Efficient RAT signature locator for bypassing AV/EDR, supporting static scanning and memory scanning.
- Updated
Oct 23, 2024 - Python
PowerShell script to terminate protected processes such as anti-malware and EDRs.
- Updated
Jun 9, 2023 - PowerShell
Windows 11 Syscall table. Ready to use in direct syscall. Actively maintained.
- Updated
Dec 4, 2021
Load shellcode via HELLGATE, Rewrite hellgate with .net framework for learning purpose.
- Updated
Jan 21, 2022 - C#
An easy-to-use and powerful Macro for Stack Spoofing.
- Updated
Jan 8, 2025 - C++
ARP Scanner, a lightweight host-alive detection tool for OPSEC.
- Updated
Nov 17, 2024 - C++
Just an obfuscation technique in a resource file in 2 possible formats
- Updated
Jan 13, 2025 - C++
Bring Your Own Scripting Interpreter - Custom Shell (PHP)
- Updated
Dec 3, 2024 - PowerShell
Improve this page
Add a description, image, and links to thebypass-edr topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with thebypass-edr topic, visit your repo's landing page and select "manage topics."