

Windows Defender Killer | 基于注册表的禁用 + BYOVD 进程终止 (C++)

Offensive Lua.

Windows 10 DLL 注入器,通过驱动程序利用 VAD 并隐藏已加载的驱动程序

A BOF that runs unmanaged PEs inline

基于多种 EDR 规避技术的 C++ 自注入型投放器。

使用动态间接系统调用实现的反射式 x64 PE/DLL 加载器

演示旨在远程执行 shellcode 的多进程注入链的 PoC

一个工具使用 Windows 筛选平台 (WFP) 来阻止端点检测与响应 (EDR) 代理向服务器报告安全事件。

Exploitation of echo_driver.sys

源生成器,用于向 C# 项目添加 D/Invoke 和间接系统调用方法。


通过NtQueryInformationFile利用NTFS列出PID的隐蔽Windows进程枚举PoC,可绕过标准监控API,并在红队行动中实现EDR规避。

IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then reflective load…

一款使用 C++ 和 MASM x64 编写的高级隐蔽 Windows 凭据转储工具。