Skip to content
View S9MF's full-sized avatar

Block or report S9MF

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

免杀

各类语言加载器、模板化、dll加载、沙箱bypass、代码混淆、exe转shellcode.....
145 repositories

Cobalt Strike Beacon Object File for bypassing UAC via the CMSTPLUA COM interface.

C 159 25 Updated Oct 9, 2022

EasyHook - The reinvention of Windows API Hooking

C 3,119 661 Updated Jan 25, 2024

Proof of concept code for thread pool based process injection in Windows.

C++ 115 13 Updated Mar 29, 2025

An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer

C++ 484 76 Updated Feb 13, 2024

一种通过进程注入实现强制关闭部分杀软进程的方法(以360安全卫士和360杀毒为例)

C++ 127 18 Updated Dec 26, 2023

A command and control framework written in rust.

Rust 320 40 Updated Feb 21, 2025

Reflective DLL Injection Made Bella

C 225 43 Updated Jan 6, 2025

Reproducing Spyboy technique, which involves terminating all EDR/XDR/AVs processes by abusing the zam64.sys driver

Go 266 47 Updated Mar 22, 2025

一款集成了DLL-Session0注入,APC注入,映射注入,线程劫持,函数踩踏,提权的工具(支持BIN加解密)

C++ 134 24 Updated Aug 13, 2024

VBS-Obfuscator-GO is a Go-based tool designed for obfuscating VBScript (VBS) files. It transforms readable VBScript code into a less recognizable form by employing random variable names and encodin…

Go 35 4 Updated Aug 14, 2024

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

C 1,642 208 Updated Nov 3, 2024

A WIP shellcode loader tool which bypasses AV/EDR, coded in C++, and equipped with a minimal console builder.

C++ 42 6 Updated Sep 1, 2024

C++ Staged Shellcode Loader with Evasion capabilities.

C++ 92 10 Updated Oct 7, 2024

Collection of various malicious functionality to aid in malware development

C++ 1,628 261 Updated Feb 28, 2024

C# Reflective loader for unmanaged binaries.

C# 428 65 Updated Jan 25, 2023

HookChain: A new perspective for Bypassing EDR Solutions

C 510 85 Updated Jan 5, 2025

This GitHub repository contains benign specimens; however, the techniques demonstrated herein could potentially be exploited for malicious purposes. Exercise discretion and responsibility in their …

C 16 5 Updated Aug 4, 2024

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

Python 1,401 180 Updated Jul 31, 2024

C# PoC implementation for bypassing AMSI via in memory patching

C# 65 17 Updated Jul 20, 2020

Shellcode loader generator with multiples features

Go 474 67 Updated Dec 31, 2024

Implementing the ghostly hollowing PE injection technique using tampered syscalls.

C 144 26 Updated Mar 9, 2025
C 96 15 Updated Sep 1, 2024

This repository contains complete resources and coding practices for malware development using Rust 🦀.

Rust 2,103 51 Updated Apr 7, 2025

A BOF that runs unmanaged PEs inline

C 590 68 Updated Oct 23, 2024

Just a simple silly PoC demonstrating executable "exe" file that can be used like exe, dll or shellcode...

C 155 27 Updated Sep 12, 2024

VM detection library and tool

C++ 531 58 Updated Apr 10, 2025

Compiletime string literal obfuscation for Rust.

Rust 518 27 Updated Oct 6, 2024

Now You See Me, Now You Don't

C++ 924 142 Updated Jan 1, 2025

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

XSLT 7,446 1,031 Updated Feb 15, 2025

LSASS memory dumper using only NTAPIs, creating a minimal minidump. It can be compiled as shellcode (PIC), supports XOR encryption, and remote file transmission.

Rust 330 42 Updated Mar 8, 2025