awesome-repositories.com
Blog
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetÀ proposNotre méthodologiePresseServeur MCP
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to ccob/sharpblock

Open-source alternatives to SharpBlock

30 open-source projects similar to ccob/sharpblock, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best SharpBlock alternative.

  • bats3c/darkloadlibraryAvatar de bats3c

    bats3c/DarkLoadLibrary

    1,180Voir sur GitHub↗

    LoadLibrary for offensive operations

    C
    Voir sur GitHub↗1,180
  • getrektboy724/sharpunhookerAvatar de GetRektBoy724

    GetRektBoy724/SharpUnhooker

    408Voir sur GitHub↗

    C# Based Universal API Unhooker - Automatically Unhook API Hives (ntdll.dll, kernel32.dll, advapi32.dll, and kernelbase.dll). SharpUnhooker helps you to evades user-land monitoring done by AVs and/or EDRs by cleansing/refreshing API DLLs that loaded on the process (Offensive Side) or remove API…

    C#
    Voir sur GitHub↗408
  • soledge/blocketwAvatar de Soledge

    Soledge/BlockEtw

    81Voir sur GitHub↗

    .Net 3.5 / 4.5 Assembly to block ETW telemetry in a process

    C#
    Voir sur GitHub↗81
  • yaxser/backstabAvatar de Yaxser

    Yaxser/Backstab

    1,516Voir sur GitHub↗

    Have these local admin credentials but the EDR is standing in the way? Unhooking or direct syscalls are not working against the EDR? Well, why not just kill it? Backstab is a tool capable of killing antimalware protected processes by leveraging sysinternals’ Process Explorer (ProcExp) driver,…

    C
    Voir sur GitHub↗1,516
  • bats3c/evtmuteAvatar de bats3c

    bats3c/EvtMute

    264Voir sur GitHub↗

    This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging.

    C#
    Voir sur GitHub↗264

Recherche par IA

Explorez plus de dépôts awesome

Décrivez vos besoins en langage naturel — l'IA classe des milliers de projets open source sélectionnés par pertinence.

Find more with AI search
  • lolbas-project/lolbasAvatar de LOLBAS-Project

    LOLBAS-Project/LOLBAS

    8,323Voir sur GitHub↗

    LOLBAS is a curated database and knowledge base of signed Windows binaries that can be misused to bypass security restrictions and execute unauthorized code. It serves as a technical registry that maps trusted system files to their functional capabilities and the offensive tactics they enable. The project distinguishes itself by providing a capability-driven indexing system and a tactics registry that relates legitimate binary functionality to known security evasion techniques. It includes an association layer that links specific system binaries to attack patterns and tactical objectives, pro

    XSLTblueteamdfirliving-off-the-land
    Voir sur GitHub↗8,323
  • api0cradle/ultimateapplockerbypasslistAvatar de api0cradle

    api0cradle/UltimateAppLockerByPassList

    2,067Voir sur GitHub↗

    The goal of this repository is to document the most common techniques to bypass AppLocker.

    PowerShell
    Voir sur GitHub↗2,067
  • am0nsec/sharphellsgateA

    am0nsec/SharpHellsGate

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • aaaddress1/pr0cessA

    aaaddress1/PR0CESS

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • getrektboy724/triplesG

    GetRektBoy724/TripleS

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • bats3c/ghost-in-the-logsB

    bats3c/Ghost-In-The-Logs

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • bohops/ultimatewdacbypasslistB

    bohops/UltimateWDACBypassList

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • br-sn/cheekyblinderB

    br-sn/CheekyBlinder

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • call-042pe/ucantseem3C

    call-042PE/UCantSeeM3

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • forrest-orr/phantom-dll-hollower-pocF

    forrest-orr/phantom-dll-hollower-poc

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • am0nsec/hellsgateAvatar de am0nsec

    am0nsec/HellsGate

    1,202Voir sur GitHub↗

    Original C Implementation of the Hell's Gate VX Technique Link to the paper: https://vxug.fakedoma.in/papers/VXUG/Exclusive/HellsGate.pdf PDF also included in this repository. Authors: Paul Laîné (@am0nsec) smellyvx (@RtlMateusz)

    C
    Voir sur GitHub↗1,202
  • flangvik/netloaderAvatar de Flangvik

    Flangvik/NetLoader

    849Voir sur GitHub↗

    Loads any C# binary from filepath or url, patching AMSI and unhooks ETW

    C#
    Voir sur GitHub↗849
  • fashionproof/checksafebootF

    fashionproof/CheckSafeBoot

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • asaurusrex/doppelgateA

    asaurusrex/DoppelGate

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • fuzzysecurity/sharp-suiteAvatar de FuzzySecurity

    FuzzySecurity/Sharp-Suite

    1,142Voir sur GitHub↗

    Also known by Microsoft as Knifecoat :hot_pepper:

    C#
    Voir sur GitHub↗1,142
  • dewera/plutoD

    Dewera/Pluto

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • cerbersec/killdefenderbofAvatar de Cerbersec

    Cerbersec/KillDefenderBOF

    236Voir sur GitHub↗

    KillDefenderBOF is a Beacon Object File PoC implementation of pwn1sher/KillDefender which is based on research by Gabriel Landau. The article can be found here.

    C
    Voir sur GitHub↗236
  • hlldz/invoke-phant0mH

    hlldz/Invoke-Phant0m

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • hlldz/phant0mAvatar de hlldz

    hlldz/Phant0m

    1,807Voir sur GitHub↗

    Svchost is essential in the implementation of so-called shared service processes, where a number of services can share a process in order to reduce resource consumption. Grouping multiple services into a single process conserves computing resources, and this consideration was of particular…

    C
    Voir sur GitHub↗1,807
  • hlldz/reflexxionAvatar de hlldz

    hlldz/RefleXXion

    500Voir sur GitHub↗

    RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, it first collects the syscall numbers of the NtOpenFile, NtCreateSection, NtOpenSection and NtMapViewOfSection found in the LdrpThunkSignature array. After…

    C++
    Voir sur GitHub↗500
  • ionescu007/faxhellI

    ionescu007/faxhell

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • jackullrich/universal-syscall-64J

    jackullrich/universal-syscall-64

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • jfmaes/sharpnukeeventlogJ

    jfmaes/SharpNukeEventLog

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • jlospinoso/gargoyleJ

    JLospinoso/gargoyle

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • aptortellini/undefenderAvatar de APTortellini

    APTortellini/unDefender

    360Voir sur GitHub↗

    unDefender is the C++ implementation of a technique originally described by @jonasLyk in this Twitter thread. At its core, this technique revolves around changing the \Device\BootDevice symbolic link in the Windows Object Manager so that when Defender's WdFilter driver is unloaded and loaded…

    C++
    Voir sur GitHub↗360