awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to ccob/sharpblock

Open-source alternatives to SharpBlock

30 open-source projects similar to ccob/sharpblock, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best SharpBlock alternative.

  • bats3c/darkloadlibrarybats3c 的头像

    bats3c/DarkLoadLibrary

    1,180在 GitHub 上查看↗

    LoadLibrary for offensive operations

    C
    在 GitHub 上查看↗1,180
  • getrektboy724/sharpunhookerGetRektBoy724 的头像

    GetRektBoy724/SharpUnhooker

    408在 GitHub 上查看↗

    C# Based Universal API Unhooker - Automatically Unhook API Hives (ntdll.dll, kernel32.dll, advapi32.dll, and kernelbase.dll). SharpUnhooker helps you to evades user-land monitoring done by AVs and/or EDRs by cleansing/refreshing API DLLs that loaded on the process (Offensive Side) or remove API…

    C#
    在 GitHub 上查看↗408
  • soledge/blocketwSoledge 的头像

    Soledge/BlockEtw

    81在 GitHub 上查看↗

    .Net 3.5 / 4.5 Assembly to block ETW telemetry in a process

    C#
    在 GitHub 上查看↗81
  • yaxser/backstabYaxser 的头像

    Yaxser/Backstab

    1,516在 GitHub 上查看↗

    Have these local admin credentials but the EDR is standing in the way? Unhooking or direct syscalls are not working against the EDR? Well, why not just kill it? Backstab is a tool capable of killing antimalware protected processes by leveraging sysinternals’ Process Explorer (ProcExp) driver,…

    C
    在 GitHub 上查看↗1,516
  • bats3c/evtmutebats3c 的头像

    bats3c/EvtMute

    264在 GitHub 上查看↗

    This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging.

    C#
    在 GitHub 上查看↗264

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Find more with AI search
  • lolbas-project/lolbasLOLBAS-Project 的头像

    LOLBAS-Project/LOLBAS

    8,323在 GitHub 上查看↗

    LOLBAS is a curated database and knowledge base of signed Windows binaries that can be misused to bypass security restrictions and execute unauthorized code. It serves as a technical registry that maps trusted system files to their functional capabilities and the offensive tactics they enable. The project distinguishes itself by providing a capability-driven indexing system and a tactics registry that relates legitimate binary functionality to known security evasion techniques. It includes an association layer that links specific system binaries to attack patterns and tactical objectives, pro

    XSLTblueteamdfirliving-off-the-land
    在 GitHub 上查看↗8,323
  • api0cradle/ultimateapplockerbypasslistapi0cradle 的头像

    api0cradle/UltimateAppLockerByPassList

    2,067在 GitHub 上查看↗

    The goal of this repository is to document the most common techniques to bypass AppLocker.

    PowerShell
    在 GitHub 上查看↗2,067
  • am0nsec/sharphellsgateA

    am0nsec/SharpHellsGate

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • aaaddress1/pr0cessA

    aaaddress1/PR0CESS

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • getrektboy724/triplesG

    GetRektBoy724/TripleS

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • bats3c/ghost-in-the-logsB

    bats3c/Ghost-In-The-Logs

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • bohops/ultimatewdacbypasslistB

    bohops/UltimateWDACBypassList

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • br-sn/cheekyblinderB

    br-sn/CheekyBlinder

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • call-042pe/ucantseem3C

    call-042PE/UCantSeeM3

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • forrest-orr/phantom-dll-hollower-pocF

    forrest-orr/phantom-dll-hollower-poc

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • am0nsec/hellsgateam0nsec 的头像

    am0nsec/HellsGate

    1,202在 GitHub 上查看↗

    Original C Implementation of the Hell's Gate VX Technique Link to the paper: https://vxug.fakedoma.in/papers/VXUG/Exclusive/HellsGate.pdf PDF also included in this repository. Authors: Paul Laîné (@am0nsec) smellyvx (@RtlMateusz)

    C
    在 GitHub 上查看↗1,202
  • flangvik/netloaderFlangvik 的头像

    Flangvik/NetLoader

    849在 GitHub 上查看↗

    Loads any C# binary from filepath or url, patching AMSI and unhooks ETW

    C#
    在 GitHub 上查看↗849
  • fashionproof/checksafebootF

    fashionproof/CheckSafeBoot

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • asaurusrex/doppelgateA

    asaurusrex/DoppelGate

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • fuzzysecurity/sharp-suiteFuzzySecurity 的头像

    FuzzySecurity/Sharp-Suite

    1,142在 GitHub 上查看↗

    Also known by Microsoft as Knifecoat :hot_pepper:

    C#
    在 GitHub 上查看↗1,142
  • dewera/plutoD

    Dewera/Pluto

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • cerbersec/killdefenderbofCerbersec 的头像

    Cerbersec/KillDefenderBOF

    236在 GitHub 上查看↗

    KillDefenderBOF is a Beacon Object File PoC implementation of pwn1sher/KillDefender which is based on research by Gabriel Landau. The article can be found here.

    C
    在 GitHub 上查看↗236
  • hlldz/invoke-phant0mH

    hlldz/Invoke-Phant0m

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • hlldz/phant0mhlldz 的头像

    hlldz/Phant0m

    1,807在 GitHub 上查看↗

    Svchost is essential in the implementation of so-called shared service processes, where a number of services can share a process in order to reduce resource consumption. Grouping multiple services into a single process conserves computing resources, and this consideration was of particular…

    C
    在 GitHub 上查看↗1,807
  • hlldz/reflexxionhlldz 的头像

    hlldz/RefleXXion

    500在 GitHub 上查看↗

    RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, it first collects the syscall numbers of the NtOpenFile, NtCreateSection, NtOpenSection and NtMapViewOfSection found in the LdrpThunkSignature array. After…

    C++
    在 GitHub 上查看↗500
  • ionescu007/faxhellI

    ionescu007/faxhell

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • jackullrich/universal-syscall-64J

    jackullrich/universal-syscall-64

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • jfmaes/sharpnukeeventlogJ

    jfmaes/SharpNukeEventLog

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • jlospinoso/gargoyleJ

    JLospinoso/gargoyle

    0在 GitHub 上查看↗
    在 GitHub 上查看↗0
  • aptortellini/undefenderAPTortellini 的头像

    APTortellini/unDefender

    360在 GitHub 上查看↗

    unDefender is the C++ implementation of a technique originally described by @jonasLyk in this Twitter thread. At its core, this technique revolves around changing the \Device\BootDevice symbolic link in the Windows Object Manager so that when Defender's WdFilter driver is unloaded and loaded…

    C++
    在 GitHub 上查看↗360