A modern tool for Windows kernel exploration and tracing with a focus on security
-
Updated
Mar 31, 2023 - Go
A modern tool for Windows kernel exploration and tracing with a focus on security
An Active Defense and EDR software to empower Blue Teams
Enumerate and disable common sources of telemetry used by AV/EDR.
Evasive shellcode loader for bypassing event-based injection detection (PoC)
iMonitor(冰镜 - 终端行为分析系统)
a tool to help operate in EDRs' blind spots
Owlyshield is an EDR framework designed to safeguard vulnerable applications from potential exploitation (C&C, exfiltration and impact).
戎码之眼是一个window上的基于att&ck模型的威胁监控工具.有效检测常见的未知威胁与已知威胁.防守方的利剑
系统监控开发套件(sysmon、promon、edr、终端安全、主机安全、零信任、上网行为管理)
Test the accuracy of Endpoint Detection and Response (EDR) software with simple script which executes various ATT&CK/LOLBAS/Invoke-CradleCrafter/Invoke-DOSfuscation payloads
PoC memory injection detection agent based on ETW, for offensive and defensive research purposes
Sysmon EDR POC Build within Powershell to prove ability.
Carbon Black API - Python language bindings
Add a description, image, and links to the edr topic page so that developers can more easily learn about it.
To associate your repository with the edr topic, visit your repo's landing page and select "manage topics."