
HashDump-BypassEDR
Windows绕过EDR实现DumpHash
hash-analysisids-ips-evasionpassword-attacks+3
2621 month ago

Windows绕过EDR实现DumpHash

collection of apis used in malware development

Mutates signed Windows binaries to retain valid catalog signatures while changing file hashes, bypassing hash-based endpoint blocks and exposing…

Randomly changes Win32/64 PE Files for 'safer' uploading to malware and sandbox sites.