ahron-chet / EDR-anti-hooking-PoC

A tool that bypasses Microsoft EDR by manually loading DLLs, parsing EAT directly, and updating IAT with unhooked functions to run Mimikatz in-memory. The project includes an LSASS dumper that uses a callback function and memory manipulations to bypass Windows Defender

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

ahron-chet/EDR-anti-hooking-PoC Stargazers