
Voidgate
A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

仅使用DNS的命令与控制框架,支持Windows代理、载荷生成、远程Shell执行、Shellcode注入及SOCKS5代理,用于隐蔽行动。

利用合法的 WFP 标注驱动程序来阻止 EDR 代理发送遥测数据

通过插入垃圾数据绕过 WAF 的 Burp 插件

.NET 程序集加载器,带无补丁 AMSI 与 ETW 绕过功能

HookChain: A new perspective for Bypassing EDR Solutions

Linux后渗透代理,利用io_uring通过避免传统系统调用来隐蔽地绕过EDR检测。

🧙♂️ 用于脚本劫持存在漏洞的 Electron 应用的 Node.js 命令与控制

Linux 上的地表之下生存 ~ Bsides Belfast/Vienna 2025


在 Windows 上,通过反沙箱检测、ntdll 解钩、动态 API 解析及多层 shellcode 混淆(XOR/RC4/Base64/MAC)来规避杀毒软件与沙箱。

Obex – Blocking unwanted DLLs in user mode

用于通过线程池代理 Nt API 调用的 Crystal Palace 库

RunPE 实现,具有多种规避技术 (2)

Remove API hooks from a Beacon process.


Remove API hooks from a Beacon process.

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.