dsnezhkov / zombieant

Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Zombie Ant Farm: A Kit For Playing Hide and Seek with Linux EDRs.

Version 0.5-alpha

Why?

Because monolithic offensive tools are never enough and building your own offensive strategies and tools is fun.

What?

  • Offensive Preloading Primitives and Building Blocks.
  • Distributed Payload Warehousing and Delivery Service.
  • In-Memory Payload Delivery Assistant.
  • ASLR Weakening shims
  • Reflectively evasive techniques.

Components

  • ZAF Preloaders
  • ZAF Evasion Primitives
  • ZAF Warehouse Service
  • In-memory execution and preload
  • ASRL Weakening Kits.

Please see Wiki for details

License

Released under MIT license:

THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

IBM Corporation and the author is not responsible or liable for this code or its use cases currently.

About

Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.

License:MIT License


Languages

Language:C 86.0%Language:Python 5.4%Language:Makefile 4.0%Language:Shell 3.4%Language:Lua 0.8%Language:Tcl 0.2%Language:Go 0.1%Language:Objective-C 0.0%