How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.
C# Based Universal API Unhooker - Automatically Unhook API Hives (ntdll.dll, kernel32.dll, advapi32.dll, and kernelbase.dll). SharpUnhooker helps you to evades user-land monitoring done by AVs and/or EDRs by cleansing/refreshing API DLLs that loaded on the process (Offensive Side) or remove API…
This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging.
LoadLibrary for offensive operations
The main features of bats3c/darkloadlibrary are: Defense Evasion, EDR and Logging Evasion.
Open-source alternatives to bats3c/darkloadlibrary include: getrektboy724/sharpunhooker — C# Based Universal API Unhooker - Automatically Unhook API Hives (ntdll.dll, kernel32.dll, advapi32.dll, and… yaxser/backstab — Have these local admin credentials but the EDR is standing in the way? Unhooking or direct syscalls are not working… bats3c/evtmute — This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event… ccob/sharpblock. soledge/blocketw — .Net 3.5 / 4.5 Assembly to block ETW telemetry in a process. lolbas-project/lolbas — LOLBAS is a curated database and knowledge base of signed Windows binaries that can be misused to bypass security…