Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
AV-EDR-Lab-Environment-Setup — مراجع إعداد بيئة مختبر AV/EDR للمساعدة في تطوير البرمجيات الخبيثة | Kitploit
أدوات/GitHubGitHub/an0nud4y/av-edr-lab-environment-setup
أدوات دفاعيةالتهرب من IDS/IPSتحليل البرمجيات الخبيثةكشف التسللالتعلم والتعليمالفريق الأحمرموارد منسقةتطوير الحمولاتمختبرات وتدريب عملي

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
GitHuban0nud4y/av-edr-lab-environment-setup

AV-EDR-Lab-Environment-Setup

مراجع إعداد بيئة مختبر AV/EDR للمساعدة في تطوير البرمجيات الخبيثة

عرض المستودع
470412منذ سنة واحدةتمت المراجعة من قبل Kitploit

إعداد بيئة مختبر AV/EDR

تم أخذه في البداية من Maldev Academy Discord وأضيفت إليه المزيد من الموارد.

ملاحظات Notion : https://an0nud4y.notion.site/AV-EDR-Lab-Env-Setup-130bc870022d8071935cc682d3eb34b9?pvs=4

  • مثال على الأشياء التي يمكن استخدامها لمحاكاة بعض الميزات التي تمتلكها حلول EDR المدفوعة:

    • SACL - sysmon

      • https://detect.fyi/sysmon-a-viable-alternative-to-edr-44d4fbe5735a?gi=eb4475ea6b3d
      • https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/active-directory-hunting-set-up-advanced-monitoring-with-sysmon/m-p/3977120
      • Sysmon Config : https://github.com/SwiftOnSecurity/sysmon-config
    • HOOKS

      • bitdefender free : https://otterhacker.github.io/Malware/Function hooking.html
      • HookDetector (يكتشف جميع واجهات API المُثبت عليها خطافات) : https://github.com/matterpreter/OffensiveCSharp/tree/master/HookDetector
      • TelemetrySourcerer (تعداد وتعطيل المصادر الشائعة للتيليمتري المستخدمة من قبل AV/EDR، بما في ذلك ETW، خطافات وضع المستخدم، واستدعاءات النواة) : https://github.com/jthuraisamy/TelemetrySourcerer
    • كشف استدعاءات النظام اليدوية من وضع المستخدم

      • https://github.com/jackullrich/syscall-detect
      • تعليق العملية الحالية لتحديد عمليات تنفيذ استدعاءات النظام اليدوية على Windows : https://github.com/paranoidninja/Process-Instrumentation-Syscall-Hook
      • Hunt-Weird-Syscalls : https://github.com/thefLink/Hunt-Weird-Syscalls
    • PROCESS/PESCAN

      • Yapscan - اجمع أكبر عدد ممكن من قواعد YARA
      • DetectItEasy(DIE) : https://github.com/horsicq/Detect-It-Easy
    • AMSI Provider

      • AMSI Provider : https://github.com/jborean93/AmsiProvider
    • مزوّدو/مستهلكو ETW-TI/ETW -

      • silketw : https://otterhacker.github.io/Malware/ETW.html
      • ETWInspector : https://github.com/jsecurity101/ETWInspector
      • سرد مزوّدي ETW لعملية معينة : https://github.com/whokilleddb/ETWListicle
      • KrabsETW (مستهلك ETW من Microsoft) : https://github.com/microsoft/krabsetw
      • BlueKrabsETW (لفرق الدفاع، مبني على KrabsETW من Microsoft) : https://github.com/threathunters-io/bluekrabsetw
      • SealighterTI (مزوّد ETW لاستخبارات التهديدات) : https://github.com/pathtofile/SealighterTI
      • TiEtwAgent (كشف حقن الذاكرة بالاعتماد على ETW-TI) : https://github.com/xuanxuan0/TiEtwAgent
      • PyWinTrace (مكتبة ETW للغة Python) : https://github.com/fireeye/pywintrace
      • EtwExplorer (عرض بيان مزوّدي ETW) : https://github.com/zodiacon/EtwExplorer
      • TelemetrySourcerer (تعداد وتعطيل المصادر الشائعة للتيليمتري المستخدمة من قبل AV/EDR، بما في ذلك ETW، خطافات وضع المستخدم، واستدعاءات النواة) : https://github.com/jthuraisamy/TelemetrySourcerer
      • MentalTi (محلل ETWTi) : https://github.com/mannyfred/MentalTi
      • PockETWatcher : https://github.com/olafhartong/PockETWatcher
      • موارد ETW
        • يحتوي على موارد لتعلّم وفهم EVTX/ETW (تتبع الأحداث في Windows) : https://github.com/nasbench/EVTX-ETW-Resources
    • استدعاءات النواة -

      • Elastic
      • Sysmon
      • TelemetrySourcerer (تعداد وتعطيل المصادر الشائعة للتيليمتري المستخدمة من قبل AV/EDR، بما في ذلك ETW، خطافات وضع المستخدم، واستدعاءات النواة) : https://github.com/jthuraisamy/TelemetrySourcerer
    • Capa - فحص القدرات

    • تتبع استدعاءات API - TinyTracer

      • https://github.com/hasherezade/tiny_tracer
  • اجمع تيليمتري Windows لتطوير البرمجيات الخبيثة

    • يجمع تيليمتري مثل ETW، ETW-TI، استدعاءات النواة، الخطافات، مكدسات الاستدعاء، ملفات DLL المحملة، PEB) : https://github.com/dobin/RedEdr ، واجهة RedEDR UI (https://github.com/dobin/RedEdrUi) (اطلع على مشاريع أخرى للمؤلف)
  • تجارب مجانية لمنتجات EDR/AV

    • Microsoft Defender For Endpoint
      • https://medium.com/@hackenbacker/creating-a-defender-for-endpoint-lab-for-free-695044b75bd6
      • https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-trial-user-guide
    • Sophos XDR (تجريبي)
    • Elastic EDR
      • https://github.com/sherifabdlnaby/elastdocker
      • https://otterhacker.github.io/Malware/Elastic EDR.html
      • https://github.com/peasead/elastic-container
      • https://www.youtube.com/watch?v=1luhjL7TN9U
    • TrendMicro
    • McAfee MVISION
    • Avast
    • openEDR - EDR المجاني من Comodo
    • Wazuh : https://github.com/wazuh/wazuh
    • Huntress Managed EDR - (15 يومًا تجربة مجانية، بدون الحاجة إلى بطاقة ائتمان، 3 تقارير عن حوادث عالية/حرجة من محللي SOC في الوقت الفعلي) : https://www.huntress.com/edr-free-trial
  • EDRs مفتوحة المصدر

    • RedEDR : https://github.com/dobin/RedEdr
    • SimpleEDR - تعليق يدوي لمكتبات DLL للعثور على فرصة كشف : https://github.com/Helixo32/SimpleEDR
    • CrimsonEDR : https://github.com/Helixo32/CrimsonEDR
    • OpenEDR : https://github.com/ComodoSecurity/openedr/
    • InjDrv : https://github.com/wbenny/injdrv
    • MyDumbEDR : https://github.com/sensepost/mydumbedr
    • BestEDROfTheMarket : https://github.com/Xacone/BestEdrOfTheMarket
    • JonMon : https://github.com/jsecurity101/JonMon
    • SylantStrike : https://github.com/CCob/SylantStrike
    • Whids : https://github.com/0xrawsec/whids
    • اكتب EDR خاصًا بك
      • https://blog.whiteflag.io/blog/from-windows-drivers-to-a-almost-fully-working-edr/
      • https://youtube.com/playlist?list=PLc2_LEyTNutFkUliQMTZ_FHl8kNx3f5-E&si=8kHcC_FIxccHBR5H
      • https://sensepost.com/blog/2024/sensecon-23-from-windows-drivers-to-an-almost-fully-working-edr/
  • مقارنة EDRs مفتوحة المصدر بواسطة @dobin

    Open-Source-EDR-Comparison.png

  • ماسحات أحداث تحميل الصور

    • Hunt-Weird-ImageLoads : https://github.com/thefLink/Hunt-Weird-ImageLoads
  • ماسحات ذاكرة العمليات

    • PE-sieve : https://github.com/hasherezade/pe-sieve
    • Moneta : https://github.com/forrest-orr/moneta
    • YapScan : https://github.com/fkie-cad/yapscan
    • MalMemDetect : https://github.com/waldo-irc/MalMemDetect
    • Patriot : https://github.com/joe-desimone/patriot
    • Hunt-Sleeping-Beacons : https://github.com/thefLink/Hunt-Sleeping-Beacons
    • YaraMemoryScanner : https://github.com/BinaryDefense/YaraMemoryScanner
    • ماسحات مخصصة لكشف Beacons الخاصة بـ Cobalt Strike
      • BeaconEye : https://github.com/CCob/BeaconEye
      • BeaconHunter : https://github.com/3lp4tr0n/BeaconHunter
    • EtwTi-FluctuationMonitor - تنفيذ VirtualAlloc(RWX) يغيّر مخطط CFG وفقًا لذلك، وبعد VirtualAlloc(RW) يبقى CFG كما هو : https://github.com/jdu2600/EtwTi-FluctuationMonitor
      • https://github.com/jdu2600/CFG-FindHiddenShellcode
      • https://github.com/jdu2600/Etw-SyscallMonitor
    • TiEtwAgent (كشف حقن الذاكرة بالاعتماد على ETW-TI) : https://github.com/xuanxuan0/TiEtwAgent
  • تجاوز كشف التوقيعات

    • ThreatCheck : https://github.com/PACHAKUTlQ/ThreatCheck
    • AvRed : https://github.com/dobin/avred

إعداد جهاز تطوير البرمجيات الخبيثة

  • تجنّب استخدام Windows إذا كنت قلقًا بشأن تيليمتري Windows أثناء كتابة برمجياتك الخبيثة.
  • Tiny11Builder (لإزالة العديد من مكونات Windows غير الضرورية بما في ذلك التيليمتري) (مأخوذ من هنا) : https://github.com/ntdevlabs/tiny11builder

دواخل AV/EDR / التيليمتري / قياس الأداء / آلية العمل

  • دواخل EDR

    • Matt Hand - كتاب Evading EDR
    • كيف يعمل EDR (مرجع مكافحة EDR الشامل) : https://blog.deeb.ch/posts/how-edr-works/
  • محاضرات حول دواخل/عمل EDR

    • https://youtu.be/SYM4i474JqM?si=ak5fBhcMmHxsopUn
    • https://youtu.be/CKfjLnEMfvI?si=2iiKBt1El9PGnhEt
    • https://www.youtube.com/live/VwpTyS7l5yo?si=djCZpKyWHGm8042-
    • https://youtu.be/vdYdKmgm20U?si=KIUNis9VrO4clSqF
  • تيليمتري EDR - تيليمتري EDR المتنوعة : https://github.com/tsale/EDR-Telemetry

    • https://www.edr-telemetry.com/
    • جدول بيانات تيليمتري EDR : https://docs.google.com/spreadsheets/u/1/d/1ZMFrD6F6tvPtf_8McC-kWrNBBec_6Si3NW6AoWf3Kbg/htmlview
  • Defender Harvester : https://github.com/olafhartong/DefenderHarvester

  • قوائم خطافات EDR : https://github.com/Mr-Un1k0d3r/EDRs

    • HookDetector (يكتشف جميع واجهات API المُثبت عليها خطافات) : https://github.com/matterpreter/OffensiveCSharp/tree/master/HookDetector
  • Polonium : أداة من دورة Modern Initial Access and Evasion Tactics من إعداد Binary-Offensive (@mariuszbit). https://github.com/sponsors/mgeeky

  • تيليمتري خطافات EDR

    EDR-Hooks-Telemetry
    • مأخوذ من : https://github.com/helviojunior/hookchain/blob/main/HookChain_en_v1.5.pdf

الشكر والتقدير

  • شكرًا لأعضاء MaldevAcademy Discord على القائمة الأولية
  • شكرًا لـ @dobin ، لتوفيره قائمة بموارد إضافية وجدول مقارنة EDRs مفتوحة المصدر.
  • شكرًا لـ @fin3ss3g0d ، لمشاركته حول عرض Huntress Managed EDR التجريبي.
تنزيل الأداة
  • مربع Gartner السحري لمنصات EDR

    <img src="https://raw.githubusercontent.com/An0nUD4Y/AV-EDR-Lab-Environment-Setup/main/Images/Gartner"s-Magic-Quadrant.png" alt="Gartner's-Magic-Quadrant" width="500"/>

    • مأخوذ من : https://github.com/helviojunior/hookchain/blob/main/HookChain_en_v1.5.pdf