There are 28 repositories under edr topic.
Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It is derived from ByteDance's internal best practices.
Adversary tradecraft detection, protection, and hunting
AV/EDR Evasion Lab for Training & Learning Purposes
Awesome EDR Bypass Resources For Ethical Hacking
Evasive shellcode loader for bypassing event-based injection detection (PoC)
Enumerate and disable common sources of telemetry used by AV/EDR.
iMonitor(冰镜 - 终端行为分析系统)
Threat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint.
Cobalt Strike script for ScareCrow payloads intergration (EDR/AV evasion)
Owlyshield is an EDR framework designed to safeguard vulnerable applications from potential exploitation (C&C, exfiltration and impact).
Unlock the full brightness of the XDR display of your MacBook Pro
The world's most powerful System Activity Monitor Engine · 一款功能强大的终端行为采集防御开发套件 ~ 旨在帮助EDR、零信任、数据安全、审计管控等终端安全软件可以快速实现产品功能, 而不用关心底层驱动的开发、维护和兼容性问题,让其可以专注于业务开发
CSS trick/bug to display a brighter white by exploiting browsers' HDR capability and Apple's EDR system
Test the accuracy of Endpoint Detection and Response (EDR) software with simple script which executes various ATT&CK/LOLBAS/Invoke-CradleCrafter/Invoke-DOSfuscation payloads
Replace the .txt section of the current loaded modules from \KnownDlls\ to bypass edrs
Hades HIDS/HIPS for Windows
PoC memory injection detection agent based on ETW, for offensive and defensive research purposes
MDE Tester is designed to help testing various features in Microsoft Defender for Endpoint.
Yet another C++ Cobalt Strike beacon dropper with Compile-Time API hashing and custom indirect syscalls execution
A Dropper POC with a focus on aiding in EDR evasion, NTDLL Unhooking followed by loading ntdll in-memory, which is present as shellcode (using pe2shc by @hasherezade). Payload encryption via SystemFucntion033 NtApi and No new thread via Fiber
kernel callback removal (Bypassing EDR Detections)
A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.
An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.
Carbon Black API - Python language bindings
Free and Open Source alternative to Vivid macOS application to extend Apple XDR display brightness from 500 up to 1600 nits.