evasionedr Goto Github PK
Type: Organization
Type: Organization
Lists of .NET Obfuscator (Free, Freemium, Paid and Open Source )
x64 binary obfuscator
Depending on the AV/EDR we will check which Windows APIs are hooked by the AV/EDR
Single stub direct and indirect syscalling with runtime SSN resolving for windows.
A PoC implementation for dynamically masking call stacks with timers.
This project was for my senior capstone at the University of Arizona. I wanted to create a payload that would potentially bypass AV / EDR products using techniques that negate or circumvent detection techniques used by these products.
A POC of the ContainYourself research presented in DEF CON 31, which abuses the Windows containers framework to bypass EDRs.
Extracted Yara rules from Defender mpavbase.vdm and mpasbase
Fast Conversion Windows Dynamic Link Library To ShellCode
Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters
Exploitation of echo_driver.sys
Reduce Entropy And Obfuscate Youre Payload With Serialized Linked Lists
A simple program to hook the current process to identify the manual syscall executions on windows
memory evasion and detect mechanisms
Use hardware breakpoints to spoof the call stack for both syscalls and API calls
Janus is a pre-build event that performs string obfuscation during compile time. This project is based off the CIA's Marble Framework
I will be uploading all the codes which I created with the help either opensource projects or blogs. This is a step by step EDR learning path for me.
POC code to crash Windows Event Logger Service
Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs
Run Your Payload Without Running Your Payload
Implant drop-in for EDR testing
different ntdll unhooking techniques : unhooking ntdll from disk, from KnownDlls, from suspended process, from remote server (fileless)
MAC, IPv4, UUID shellcode Loaders and Obfuscators to obfuscate the shellcode and using some native API to converts it to it binary format and loads it.
A program for obfuscating C strings
Splitting and executing shellcode across multiple pages
this repo contains 6 AMSI patches , both force the triggering of a conditional jump inside AmsiOpenSession() that close the Amsi scanning session. The 1st patch by corrupting the Amsi context header and the 2nd patch by changing the string "AMSI" that will be compared to the Amsi context header to "D1RK". The other just set ZF to 1.
Default Detections for EDR
[壳] Multi-Packer allowing to daisy-chain over 29 packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts watermarking, IOCs collection & PE Backdooring. You feed it with your implant, it does a lot of sneaky things and spits out obfuscated executable.
PPID Spoofing
绕3环的shellcode免杀框架
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.