awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektÜber unsRanking-MethodikPresseMCP-Server
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to soledge/blocketw

Open-source alternatives to BlockEtw

30 open-source projects similar to soledge/blocketw, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best BlockEtw alternative.

  • bats3c/darkloadlibraryAvatar von bats3c

    bats3c/DarkLoadLibrary

    1,180Auf GitHub ansehen↗

    LoadLibrary for offensive operations

    C
    Auf GitHub ansehen↗1,180
  • bats3c/evtmuteAvatar von bats3c

    bats3c/EvtMute

    264Auf GitHub ansehen↗

    This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging.

    C#
    Auf GitHub ansehen↗264
  • yaxser/backstabAvatar von Yaxser

    Yaxser/Backstab

    1,516Auf GitHub ansehen↗

    Have these local admin credentials but the EDR is standing in the way? Unhooking or direct syscalls are not working against the EDR? Well, why not just kill it? Backstab is a tool capable of killing antimalware protected processes by leveraging sysinternals’ Process Explorer (ProcExp) driver,…

    C
    Auf GitHub ansehen↗1,516
  • ccob/sharpblockAvatar von CCob

    CCob/SharpBlock

    1,163Auf GitHub ansehen↗
    C#
    Auf GitHub ansehen↗1,163
  • getrektboy724/sharpunhookerAvatar von GetRektBoy724

    GetRektBoy724/SharpUnhooker

    408Auf GitHub ansehen↗

    C# Based Universal API Unhooker - Automatically Unhook API Hives (ntdll.dll, kernel32.dll, advapi32.dll, and kernelbase.dll). SharpUnhooker helps you to evades user-land monitoring done by AVs and/or EDRs by cleansing/refreshing API DLLs that loaded on the process (Offensive Side) or remove API…

    C#
    Auf GitHub ansehen↗408

KI-Suche

Entdecke weitere awesome Repositories

Beschreibe in einfachen Worten, was du brauchst — die KI bewertet tausende kuratierte Open-Source-Projekte nach Relevanz.

Find more with AI search
  • lolbas-project/lolbasAvatar von LOLBAS-Project

    LOLBAS-Project/LOLBAS

    8,323Auf GitHub ansehen↗

    LOLBAS is a curated database and knowledge base of signed Windows binaries that can be misused to bypass security restrictions and execute unauthorized code. It serves as a technical registry that maps trusted system files to their functional capabilities and the offensive tactics they enable. The project distinguishes itself by providing a capability-driven indexing system and a tactics registry that relates legitimate binary functionality to known security evasion techniques. It includes an association layer that links specific system binaries to attack patterns and tactical objectives, pro

    XSLTblueteamdfirliving-off-the-land
    Auf GitHub ansehen↗8,323
  • api0cradle/ultimateapplockerbypasslistAvatar von api0cradle

    api0cradle/UltimateAppLockerByPassList

    2,067Auf GitHub ansehen↗

    The goal of this repository is to document the most common techniques to bypass AppLocker.

    PowerShell
    Auf GitHub ansehen↗2,067
  • am0nsec/sharphellsgateA

    am0nsec/SharpHellsGate

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • aaaddress1/pr0cessA

    aaaddress1/PR0CESS

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • fuzzysecurity/sharp-suiteAvatar von FuzzySecurity

    FuzzySecurity/Sharp-Suite

    1,142Auf GitHub ansehen↗

    Also known by Microsoft as Knifecoat :hot_pepper:

    C#
    Auf GitHub ansehen↗1,142
  • bats3c/ghost-in-the-logsB

    bats3c/Ghost-In-The-Logs

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • bohops/ultimatewdacbypasslistB

    bohops/UltimateWDACBypassList

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • br-sn/cheekyblinderB

    br-sn/CheekyBlinder

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • call-042pe/ucantseem3C

    call-042PE/UCantSeeM3

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • flangvik/netloaderAvatar von Flangvik

    Flangvik/NetLoader

    849Auf GitHub ansehen↗

    Loads any C# binary from filepath or url, patching AMSI and unhooks ETW

    C#
    Auf GitHub ansehen↗849
  • am0nsec/hellsgateAvatar von am0nsec

    am0nsec/HellsGate

    1,202Auf GitHub ansehen↗

    Original C Implementation of the Hell's Gate VX Technique Link to the paper: https://vxug.fakedoma.in/papers/VXUG/Exclusive/HellsGate.pdf PDF also included in this repository. Authors: Paul Laîné (@am0nsec) smellyvx (@RtlMateusz)

    C
    Auf GitHub ansehen↗1,202
  • fashionproof/checksafebootF

    fashionproof/CheckSafeBoot

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • dewera/plutoD

    Dewera/Pluto

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • asaurusrex/doppelgateA

    asaurusrex/DoppelGate

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • forrest-orr/phantom-dll-hollower-pocF

    forrest-orr/phantom-dll-hollower-poc

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • cerbersec/killdefenderbofAvatar von Cerbersec

    Cerbersec/KillDefenderBOF

    236Auf GitHub ansehen↗

    KillDefenderBOF is a Beacon Object File PoC implementation of pwn1sher/KillDefender which is based on research by Gabriel Landau. The article can be found here.

    C
    Auf GitHub ansehen↗236
  • aptortellini/undefenderAvatar von APTortellini

    APTortellini/unDefender

    360Auf GitHub ansehen↗

    unDefender is the C++ implementation of a technique originally described by @jonasLyk in this Twitter thread. At its core, this technique revolves around changing the \Device\BootDevice symbolic link in the Windows Object Manager so that when Defender's WdFilter driver is unloaded and loaded…

    C++
    Auf GitHub ansehen↗360
  • getrektboy724/triplesG

    GetRektBoy724/TripleS

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • hlldz/invoke-phant0mH

    hlldz/Invoke-Phant0m

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • hlldz/phant0mAvatar von hlldz

    hlldz/Phant0m

    1,807Auf GitHub ansehen↗

    Svchost is essential in the implementation of so-called shared service processes, where a number of services can share a process in order to reduce resource consumption. Grouping multiple services into a single process conserves computing resources, and this consideration was of particular…

    C
    Auf GitHub ansehen↗1,807
  • hlldz/reflexxionAvatar von hlldz

    hlldz/RefleXXion

    500Auf GitHub ansehen↗

    RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, it first collects the syscall numbers of the NtOpenFile, NtCreateSection, NtOpenSection and NtMapViewOfSection found in the LdrpThunkSignature array. After…

    C++
    Auf GitHub ansehen↗500
  • ionescu007/faxhellI

    ionescu007/faxhell

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • jackullrich/universal-syscall-64J

    jackullrich/universal-syscall-64

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • jfmaes/sharpnukeeventlogJ

    jfmaes/SharpNukeEventLog

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0
  • aaaddress1/wowinjectorA

    aaaddress1/wowInjector

    0Auf GitHub ansehen↗
    Auf GitHub ansehen↗0