
NTDLLReflection
Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…
adversarial-attackids-ips-evasionpost-exploitation+1
307

Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle to ntdll ,…

DLL hijacking proof-of-concept that weaponizes Microsoft Defender's MpClient.dll to load Cobalt Strike, demonstrating LockBit-style defense evasion.

C++ self-Injecting dropper based on various EDR evasion techniques.