Template-Driven AV/EDR Evasion Framework
-
Updated
Nov 3, 2023 - Assembly
Template-Driven AV/EDR Evasion Framework
Lifetime AMSI bypass
PowerShell Script Obfuscator
"AMSI WRITE RAID" Vulnerability that leads to an effective AMSI BYPASS
JustEvadeBro, a cheat sheet which will aid you through AMSI/AV evasion & bypasses.
HTTP Server serving obfuscated Powershell Scripts/Payloads
A proof of concept AMSI & ETW bypass using trampolines for hooking and modifying execution flow
This PowerShell script applies a memory patch to bypass the Antimalware Scan Interface (AMSI), allowing unrestricted execution of PowerShell commands.
Bypassing amsi.dll via memory patch, simple code!
Expeditus is a loader that executes shellcode on a target Windows system. It combines several offensive techniques in order to attempt to do this with some level of stealth.
Generate obfuscated PowerShell commands using XOR logic with random keys!
Amsi bypass in go tested on 10.0.20348.0 Microsoft Windows NT 10.0.20348.0
Generator of techniques to evade AMSI in Windows. It uses random methods to generate code without signatures detectable by Windows Defender. Ideal for security research and AMSI bypass.
Repo containing PowerShell Download Cradles (oneliners)
VBA macro chain demonstrating modern EDR-evasion techniques. OSEP-grade study artifact for Windows 11 24H2 + MDE.
Patching AmsiOpenSession by forcing an error branching.
Decrypting a powershell script and executing it using scriptblock smuggling, bypassing AMSI and some telemetry.
PowerShell AMSI Bypass
Add a description, image, and links to the amsi-evasion topic page so that developers can more easily learn about it.
To associate your repository with the amsi-evasion topic, visit your repo's landing page and select "manage topics."