Code Monkey home page Code Monkey logo

evasionedr's Projects

c_syscalls icon c_syscalls

Single stub direct and indirect syscalling with runtime SSN resolving for windows.

callstackmasker icon callstackmasker

A PoC implementation for dynamically masking call stacks with timers.

capstone-project icon capstone-project

This project was for my senior capstone at the University of Arizona. I wanted to create a payload that would potentially bypass AV / EDR products using techniques that negate or circumvent detection techniques used by these products.

containyourself icon containyourself

A POC of the ContainYourself research presented in DEF CON 31, which abuses the Windows containers framework to bypass EDRs.

defenderyara icon defenderyara

Extracted Yara rules from Defender mpavbase.vdm and mpasbase

donut icon donut

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters

entropyreducer icon entropyreducer

Reduce Entropy And Obfuscate Youre Payload With Serialized Linked Lists

etwti-syscall-hook icon etwti-syscall-hook

A simple program to hook the current process to identify the manual syscall executions on windows

hw-call-stack icon hw-call-stack

Use hardware breakpoints to spoof the call stack for both syscalls and API calls

janus icon janus

Janus is a pre-build event that performs string obfuscation during compile time. This project is based off the CIA's Marble Framework

learning-edr-and-edr_evasion icon learning-edr-and-edr_evasion

I will be uploading all the codes which I created with the help either opensource projects or blogs. This is a step by step EDR learning path for me.

mangle icon mangle

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs

norunpi icon norunpi

Run Your Payload Without Running Your Payload

ntdlll-unhooking-collection icon ntdlll-unhooking-collection

different ntdll unhooking techniques : unhooking ntdll from disk, from KnownDlls, from suspended process, from remote server (fileless)

obfloader icon obfloader

MAC, IPv4, UUID shellcode Loaders and Obfuscators to obfuscate the shellcode and using some native API to converts it to it binary format and loads it.

pagesplit icon pagesplit

Splitting and executing shellcode across multiple pages

patchthatamsi icon patchthatamsi

this repo contains 6 AMSI patches , both force the triggering of a conditional jump inside AmsiOpenSession() that close the Amsi scanning session. The 1st patch by corrupting the Amsi context header and the 2nd patch by changing the string "AMSI" that will be compared to the Amsi context header to "D1RK". The other just set ZF to 1.

protectmytooling icon protectmytooling

[壳] Multi-Packer allowing to daisy-chain over 29 packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts watermarking, IOCs collection & PE Backdooring. You feed it with your implant, it does a lot of sneaky things and spits out obfuscated executable.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.