Security Researcher, SF-Express, Suanni, Redteam
NewNtdllBypassInlineHook_CSharp. Load a fresh new copy of ntdll.dll via file mapping to bypass API inline hook.
62DInvoke_shellcodeload_CSharp. ShellCodeLoader via DInvoke
60SysCall_ShellcodeLoad_Csharp. Load shellcode via syscall
55HookDetection_CSharp. HookDetection
44MappingInjection_CSharp. MappingInjection via csharp
39PEB-PPIDspoofing_Csharp. Command line & PPID spoofing
31EarlyBirdInjection_CSharp. Inject shellcode into process via "EarlyBird"
27BypassETW_CSharp. Bypassing ETW with Csharp
26Fiber_ShellcodeExecution. Using fibers to execute shellcode in a local process via csharp
26WindowsEventLogsBypass_Csharp. Bypass windows eventlogs & Sysmon
18ThreadHijacking_CSharp. Process inject technique "Thread hijacking" via csharp
16HellgateLoader_CSharp. Load shellcode via HELLGATE, Rewrite hellgate with .net framework for learning purpose.
16ProcessHollowing_CSharp. ProcessHollowing via csharp
13APC_ShellcodeExecution_CSharp. Shellcode Load or execute via "APC technic"
13BypassAMSI_CSharp. Bypass AMSI
12Simple_ShellCodeLoader_CSharp. A Simple ShellcodeLoader
11CreateThreadpoolWait_ShellcodeExecution_CSharp. Shellcode execution via CreateThreadpoolWait with Csharp
8FullDLLUnhooking_CSharp. Unhook DLL via cleaning the DLL 's .text section
8AddressOfEntryPoint_Hijack_CSharp. Shellcode injection or execution via AddressOfEntryPoint hijack.
8JIT_DEMO_Csharp. A little JIT demo to help you understander how JIT works
6AMSICheck_CSharp. A tool to detect the integrity of AmsiScanbuffer in memory ,and defend AMSI bypass
4WinDefenderKiller. Windows Defender Killer | C++ Code Disabling Permanently Windows Defender using Registry Keys
3Terminator. Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes
3PPLcontrol. Controlling Windows PP(L)s
3ProjectPics. For temp pictures
3KernelBypassSharp. C# Kernel Mode Driver to read and write memory in protected processes
3defender-detectionhistory-parser. A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables.
2EDRs. C
2test. test
1DFSCoerce. Python
1awesome-browser-exploit. awesome list of browser exploitation tutorials
1ScareCrow. ScareCrow - Payload creation framework designed around EDR bypass.
1discover. Custom bash scripts used to automate various penetration testing tasks including recon, scanning, parsing, and creating malicious payloads and listeners with Metasploit.
1NET-Obfuscate. Obfuscate ECMA CIL (.NET IL) assemblies to evade Windows Defender AMSI
1CVE-2021-40444_builders. This repo contain builders of cab file, html file, and docx file for CVE-2021-40444 exploit
1LazySign. Create fake certs for binaries using windows binaries and the power of bat files
1go-smash. Obfuscate go binaries. 混淆 go 二进制文件中的函数名
1