unhooking
Here are 10 public repositories matching this topic...
Slides and POC demo for my talk at Divizion Zero on EDR evasion titled "Evasion Adventures"
-
Updated
Jan 14, 2023 - C++
Reduce Dynamic Analysis Detection Rates With Built-In Unhooker, Anti Analysis Techniques, And String Obfuscator Modules.
-
Updated
Dec 21, 2022 - C++
Go offensive-security research library — 15+ injection methods, AMSI/ETW/ntdll-unhook evasion, sleep mask (Ekko × XOR/RC4/AES), call-stack spoof, BYOVD (RTCore64) + kernel callback removal, LSASS dump + pure-Go MSV1_0 parser w/ PPL bypass, recon (sandbox/VM/debugger/dllhijack), PE ops (sRDI/BOF/CLR), Meterpreter C2, UAC bypass, CVE-2024-30088 LPE.
-
Updated
Apr 29, 2026 - Go
AV (BitDefender) function un-hook in C
-
Updated
Aug 27, 2022 - C
Bypassing all EDR hooks while maintaining the cleanest callstack of all time with proxy calls and an exception handler.
-
Updated
Apr 5, 2026 - C
This project demonstrates simply a ssdt unhooking technique via NtLoadDriver routine in Windows 11 X64.
-
Updated
Sep 8, 2025 - C
Improve this page
Add a description, image, and links to the unhooking topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the unhooking topic, visit your repo's landing page and select "manage topics."