Jump to content
YOUR-AD-HERE
HOSTING
TOOLS
992Proxy

Locked KILLER TOOL - (EDR Evasion)


itsMe

Recommended Posts

This is the hidden content, please

It's a AV/EDR Evasion tool created to bypass security tools for learning, until now the tool is FUD.

Features:

    Module Stomping for Memory scanning evasion
    DLL Unhooking by fresh ntdll copy
    IAT Hiding and Obfuscation & API Unhooking
    ETW Patchnig for bypassing some security controls
    Included sandbox evasion techniques & Basic Anti-Debugging
    Fully obfuscated (Functions - Keys - Shellcode) by XOR-ing
    Shellcode reversed and Encrypted
    Moving payload into hallowed memory without using APIs
    GetProcAddress & GetModuleHandle Implementation by @cocomelonc
    Runs without creating new thread & Suppoers x64 and x86 arch

This is the hidden content, please

This is the hidden content, please

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.