awesome-repositories.com
Blog
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to ccob/sharpblock

Open-source alternatives to SharpBlock

30 open-source projects similar to ccob/sharpblock, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best SharpBlock alternative.

  • bats3c/darkloadlibrarybats3c avatar

    bats3c/DarkLoadLibrary

    1,180View on GitHub↗

    LoadLibrary for offensive operations

    C
    View on GitHub↗1,180
  • getrektboy724/sharpunhookerGetRektBoy724 avatar

    GetRektBoy724/SharpUnhooker

    408View on GitHub↗

    C# Based Universal API Unhooker - Automatically Unhook API Hives (ntdll.dll, kernel32.dll, advapi32.dll, and kernelbase.dll). SharpUnhooker helps you to evades user-land monitoring done by AVs and/or EDRs by cleansing/refreshing API DLLs that loaded on the process (Offensive Side) or remove API…

    C#
    View on GitHub↗408
  • soledge/blocketwSoledge avatar

    Soledge/BlockEtw

    81View on GitHub↗

    .Net 3.5 / 4.5 Assembly to block ETW telemetry in a process

    C#
    View on GitHub↗81
  • yaxser/backstabYaxser avatar

    Yaxser/Backstab

    1,516View on GitHub↗

    Have these local admin credentials but the EDR is standing in the way? Unhooking or direct syscalls are not working against the EDR? Well, why not just kill it? Backstab is a tool capable of killing antimalware protected processes by leveraging sysinternals’ Process Explorer (ProcExp) driver,…

    C
    View on GitHub↗1,516
  • bats3c/evtmutebats3c avatar

    bats3c/EvtMute

    264View on GitHub↗

    This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging.

    C#
    View on GitHub↗264

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • lolbas-project/lolbasLOLBAS-Project avatar

    LOLBAS-Project/LOLBAS

    8,323View on GitHub↗

    LOLBAS is a curated database and knowledge base of signed Windows binaries that can be misused to bypass security restrictions and execute unauthorized code. It serves as a technical registry that maps trusted system files to their functional capabilities and the offensive tactics they enable. The project distinguishes itself by providing a capability-driven indexing system and a tactics registry that relates legitimate binary functionality to known security evasion techniques. It includes an association layer that links specific system binaries to attack patterns and tactical objectives, pro

    XSLTblueteamdfirliving-off-the-land
    View on GitHub↗8,323
  • api0cradle/ultimateapplockerbypasslistapi0cradle avatar

    api0cradle/UltimateAppLockerByPassList

    2,067View on GitHub↗

    The goal of this repository is to document the most common techniques to bypass AppLocker.

    PowerShell
    View on GitHub↗2,067
  • am0nsec/sharphellsgateA

    am0nsec/SharpHellsGate

    0View on GitHub↗
    View on GitHub↗0
  • aaaddress1/pr0cessA

    aaaddress1/PR0CESS

    0View on GitHub↗
    View on GitHub↗0
  • getrektboy724/triplesG

    GetRektBoy724/TripleS

    0View on GitHub↗
    View on GitHub↗0
  • bats3c/ghost-in-the-logsB

    bats3c/Ghost-In-The-Logs

    0View on GitHub↗
    View on GitHub↗0
  • bohops/ultimatewdacbypasslistB

    bohops/UltimateWDACBypassList

    0View on GitHub↗
    View on GitHub↗0
  • br-sn/cheekyblinderB

    br-sn/CheekyBlinder

    0View on GitHub↗
    View on GitHub↗0
  • call-042pe/ucantseem3C

    call-042PE/UCantSeeM3

    0View on GitHub↗
    View on GitHub↗0
  • forrest-orr/phantom-dll-hollower-pocF

    forrest-orr/phantom-dll-hollower-poc

    0View on GitHub↗
    View on GitHub↗0
  • am0nsec/hellsgateam0nsec avatar

    am0nsec/HellsGate

    1,202View on GitHub↗

    Original C Implementation of the Hell's Gate VX Technique Link to the paper: https://vxug.fakedoma.in/papers/VXUG/Exclusive/HellsGate.pdf PDF also included in this repository. Authors: Paul Laîné (@am0nsec) smellyvx (@RtlMateusz)

    C
    View on GitHub↗1,202
  • flangvik/netloaderFlangvik avatar

    Flangvik/NetLoader

    849View on GitHub↗

    Loads any C# binary from filepath or url, patching AMSI and unhooks ETW

    C#
    View on GitHub↗849
  • fashionproof/checksafebootF

    fashionproof/CheckSafeBoot

    0View on GitHub↗
    View on GitHub↗0
  • asaurusrex/doppelgateA

    asaurusrex/DoppelGate

    0View on GitHub↗
    View on GitHub↗0
  • fuzzysecurity/sharp-suiteFuzzySecurity avatar

    FuzzySecurity/Sharp-Suite

    1,142View on GitHub↗

    Also known by Microsoft as Knifecoat :hot_pepper:

    C#
    View on GitHub↗1,142
  • dewera/plutoD

    Dewera/Pluto

    0View on GitHub↗
    View on GitHub↗0
  • cerbersec/killdefenderbofCerbersec avatar

    Cerbersec/KillDefenderBOF

    236View on GitHub↗

    KillDefenderBOF is a Beacon Object File PoC implementation of pwn1sher/KillDefender which is based on research by Gabriel Landau. The article can be found here.

    C
    View on GitHub↗236
  • hlldz/invoke-phant0mH

    hlldz/Invoke-Phant0m

    0View on GitHub↗
    View on GitHub↗0
  • hlldz/phant0mhlldz avatar

    hlldz/Phant0m

    1,807View on GitHub↗

    Svchost is essential in the implementation of so-called shared service processes, where a number of services can share a process in order to reduce resource consumption. Grouping multiple services into a single process conserves computing resources, and this consideration was of particular…

    C
    View on GitHub↗1,807
  • hlldz/reflexxionhlldz avatar

    hlldz/RefleXXion

    500View on GitHub↗

    RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, it first collects the syscall numbers of the NtOpenFile, NtCreateSection, NtOpenSection and NtMapViewOfSection found in the LdrpThunkSignature array. After…

    C++
    View on GitHub↗500
  • ionescu007/faxhellI

    ionescu007/faxhell

    0View on GitHub↗
    View on GitHub↗0
  • jackullrich/universal-syscall-64J

    jackullrich/universal-syscall-64

    0View on GitHub↗
    View on GitHub↗0
  • jfmaes/sharpnukeeventlogJ

    jfmaes/SharpNukeEventLog

    0View on GitHub↗
    View on GitHub↗0
  • jlospinoso/gargoyleJ

    JLospinoso/gargoyle

    0View on GitHub↗
    View on GitHub↗0
  • aptortellini/undefenderAPTortellini avatar

    APTortellini/unDefender

    360View on GitHub↗

    unDefender is the C++ implementation of a technique originally described by @jonasLyk in this Twitter thread. At its core, this technique revolves around changing the \Device\BootDevice symbolic link in the Windows Object Manager so that when Defender's WdFilter driver is unloaded and loaded…

    C++
    View on GitHub↗360