etw-evasion
There are 8 repositories under etw-evasion topic.
unkvolism/Fuck-Etw
Bypass the Event Trace Windows(ETW) and unhook ntdll.
EvilBytecode/Lifetime-Amsi-EtwPatch
Two in one, patch lifetime powershell console, no more etw and amsi!
Chainski/PandaLoader
A WIP shellcode loader tool which bypasses AV/EDR, coded in C++, and equipped with a minimal console builder.
0xflux/ETW-Bypass-Rust
Event Tracing for Windows EDR bypass in Rust
EvilBytecode/ETW-Patch
code snippet provided demonstrates how to patch the EtwEventWrite function in the ntdll.dll library on Windows using CGO (C Go).
Chainski/Lifetime-Amsi-EtwPatch
Loads a C# binary in memory within powershell profile, patching AMSI + ETW.
Gurpreet06/ETW-Patcher
Bypassing Event Tracing for Windows (ETW) with CSharp
B0lg0r0v/DumbETW
A proof of concept ETW consumer that captures userland events in real time, displays them, and saves them into an .etl file