🦊 Philo's Garden

Search

SearchSearch
            • Fichte
            • General
            • Hegel
            • Kant
            • Schelling
            • General
            • Critical Phenomenology
            • De Beauvoir
            • Fanon
            • General
            • Heidegger
            • Husserl
            • Levinas
            • Merleau-Ponty
            • Sartre
            • AI
            • Deleuze and Guattari
            • Derrida
            • Foucault
            • General
            • Lyotard
            • Poststructuralist Feminism
          • 20th Century French
          • Metaphilosophy
          • Posthumanism, New Materialism etc.
          • Psychoanalysis
        • Overview
        • Expired passwords
        • Techniques by Killchain Stage
        • Discord
        • SMS
        • Telegram
            • Introduction
            • Part 1 - The Why and How of EDR
          • AMSI Bypasses
          • API Hooks
          • Callstack Monitoring
          • Custom loaders
          • Direct and Indirect Syscalls
          • ELAM Drivers
          • ETW
          • Filesystem Minifilter Drivers
          • Heap Monitoring
          • IAT Hooking
          • Image Load and Registry Monitoring
          • In-memory Encryption
          • KAPC Injection
          • Labs
          • Network Filter Drivers
          • Overview
          • PPID Spoofing
          • Process and Thread Creation Monitoring
          • Reflective Module Loadig
          • ROP Mitigations
          • RunHTMLApplication Defender Bypass
          • Sandbox Escapes
          • Shellcode Injection
          • SSN Hooking and Crushing
          • ThreadlessInject
          • SSH
        • bin2bin obfuscation
        • String obfuscation
        • UAC Bypasses
        • CVE-2023-2598 (Linux Kernel LPE via io_uring OOB)
        • CVE-2023-4427 (OOB index read in Chrome 115.0.5790.114)
        • CVE-2023-46251 (Stored DOM XSS in MyBB)
        • CVE-2023-46604 (Apache ActiveMQ RCE)
        • CVE-2023-48788 (Fortinet FortiClient EMS SQLi > RCE) one-liner
        • CVE-2023-49105 (Privesc and RCE in ownCloud)
        • CVE-2024-21887 (Authenticated Command Injection in Ivanti Connect and Policy Secure)
          • AWS Stuff
          • Azure Stuff
          • GCP Stuff
          • IAM
          • Non-hyperscalers
        • Access (general)
        • Business stuff
        • Container Stuff
        • DNS
        • Email
        • Environment segregation
        • IaC
        • Immutable OS Stuff
        • K8s
        • Logging
        • Metrics
        • Migration
        • Secrets Management
        • Security Labs
        • Phishing
        • Index
        • Part 1 - Introduction
        • README
        • Case Studies
        • Environment Detection and Disruption
        • Random
        • SMS
        • SSH
        • UAC Bypasses
              • Index
        • Cloud and SaaS
        • CTI-based
        • Darkweb
        • Domains and DNS + IPs
        • Email
        • Hunting through source code for secrets
        • Phone
        • Search Engines
        • Username
        • Web
        • WiFi and RF
          • Shells
          • SQLi
          • WAF Bypass
          • XSS
        • Content Security Policy (CSP)
        • Recon
    Home

    ❯

    Tech

    ❯

    Evasion

    ❯

    EDR Evasion

    ❯

    AMSI Bypasses

    AMSI Bypasses

    Oct 08, 20241 min read

    SharpKiller

    Lifetime AMSI-bypass for .NET Framework 4.8. Not sufficiently OPSEC-safe as is, need to modify before use

    https://github.com/S1lkys/SharpKiller

    Mitigation

    Graph View

    • SharpKiller
    • Mitigation

    Backlinks

    • No backlinks found

    Created with Quartz v4.2.3 © 2024

    • GitHub
    • Discord Community