
fake-sandbox
👁🗨 This script will simulate fake processes of analysis sandbox/VM software that some malware will try to avoid.

👁🗨 This script will simulate fake processes of analysis sandbox/VM software that some malware will try to avoid.

This program is designed to demonstrate various process injection techniques

PoCs and tools for investigation of Windows process execution techniques

Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a…

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)

An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer

C# Azure Function with an HTTP trigger that generates obfuscated PowerShell snippets that break or disable AMSI for the current process.

Python-based crypter that encrypts source code with AES-256 and Base64, evades VM detection via registry, process, and MAC checks, and executes…

A shellcode function to encrypt a running process image when sleeping.

Remove API hooks from a Beacon process.

SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using…

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

different ntdll unhooking techniques : unhooking ntdll from disk, from KnownDlls, from suspended process, from remote server (fileless)

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

Fileless x64 Assembly C2 framework with dual-channel ICMP/DNS protocol pivoting, direct syscall execution, and ptrace-based process injection for…

Hides Process From Task Manager Using NT API Hooking (NtQuerySystemInformation)