Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".
-
Updated
May 23, 2025 - C
Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".
🐍 Double Venom (DVenom) is a tool that provides an encryption wrapper and loader for your shellcode.
A simple and stealthy reverse shell written in Nim that bypasses Windows Defender detection. This tool allows you to establish a reverse shell connection with a target system. Use responsibly for educational purposes only.
Rust malware EDR evasion via direct syscalls, fully implemented as an example in Rust
Cross platform (Linux / Windows) shellcode packer for CTFs and pentest / red team exams aiming for AV evasion !
ShadeLoader is a shellcode loader designed to bypass most antivirus software. 壳代码, 杀毒软件, 绕过
The provided Python program, Inject-EXE.py, allows you to combine a malicious executable with a legitimate executable, producing a single output executable. This output executable will contain both the malicious and legitimate executables.
How to bypass windows defender by forcing uac
Bypass Windows Defender with a persistent staged reverse shell using C code & metasploit framework
Red Teaming Tactics and Techniques
Generate obfuscated PowerShell commands using XOR logic with random keys!
Hybrid Encryption Dropper with HWID system.
A simple, obfuscated in-memory injection script written in PowerShell that bypasses Windows Defender
Windows RAT w/ antivirus bypass.
Anti Malware Scan Interface (DLL) Bypass
WinRM Reverse Shell Using Powershell.
Repository to publish your evasion techniques and contribute to the project
Add a description, image, and links to the antivirus-bypass topic page so that developers can more easily learn about it.
To associate your repository with the antivirus-bypass topic, visit your repo's landing page and select "manage topics."