Skip to content
View DamonMohammadbagher's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report DamonMohammadbagher

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
90 stars written in C++
Clear filter

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

C++ 11,590 1,733 Updated Jan 31, 2025

A Tunnel which Turns UDP Traffic into Encrypted UDP/FakeTCP/ICMP Traffic by using Raw Socket,helps you Bypass UDP FireWalls(or Unstable UDP Environment)

C++ 7,476 1,179 Updated Jun 10, 2024

Windows memory hacking library

C++ 4,931 1,354 Updated Jan 26, 2024

Advanced usermode anti-anti-debugger. Forked from https://bitbucket.org/NtQuery/scyllahide

C++ 3,554 442 Updated Jun 4, 2024

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

C++ 3,206 441 Updated Dec 14, 2024

Open EDR public repository

C++ 2,338 455 Updated Jan 13, 2024

Alternative Shellcode Execution Via Callbacks

C++ 1,500 305 Updated Nov 11, 2022

This project has been moved to:

C++ 1,461 118 Updated Apr 7, 2021

Great explanation of Process Hollowing (a Technique often used in Malware)

C++ 1,287 223 Updated Oct 11, 2023

An Active Defense and EDR software to empower Blue Teams

C++ 1,249 170 Updated Aug 10, 2023

Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the intentions of a process.

C++ 1,118 219 Updated Jul 5, 2023

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners and analysts.

C++ 1,071 177 Updated Jun 17, 2022

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

C++ 1,002 138 Updated Dec 11, 2023

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

C++ 977 157 Updated Jun 17, 2022

A Simple Ransomware Vaccine

C++ 951 124 Updated Nov 8, 2023

Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes

C++ 939 157 Updated Jun 20, 2023

kill anti-malware protected processes ( BYOVD) ( Microsoft Won)

C++ 918 137 Updated Jul 21, 2023

Tool to bypass LSA Protection (aka Protected Process Light)

C++ 916 137 Updated Dec 4, 2022

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

C++ 909 192 Updated Aug 29, 2023

Run a Exe File (PE Module) in memory (like an Application Loader)

C++ 875 169 Updated Mar 28, 2021

Pinjectra is a C/C++ OOP-like library that implements Process Injection techniques (with focus on Windows 10 64-bit)

C++ 804 157 Updated Mar 10, 2022

Enumerate and disable common sources of telemetry used by AV/EDR.

C++ 779 127 Updated Mar 11, 2021

Killer is a simple tool designed to bypass AV/EDR security tools using various evasive techniques.

C++ 775 124 Updated Jul 2, 2024

Evasive shellcode loader for bypassing event-based injection detection (PoC)

C++ 743 122 Updated Aug 23, 2021

PoC Implementation of a fully dynamic call stack spoofer

C++ 734 97 Updated Jul 20, 2024

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

C++ 725 86 Updated Mar 16, 2024

HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.

C++ 647 100 Updated Jul 19, 2023

Black Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled DSE while maintaining its full functionality.

C++ 630 109 Updated Nov 9, 2023

KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.

C++ 627 155 Updated Nov 12, 2024
Next