Powerful Kernel Malware Investigation Platform | Software Analysis & Threat Hunting
-
Updated
Sep 14, 2026 - C#
Powerful Kernel Malware Investigation Platform | Software Analysis & Threat Hunting
HookDetection
Shellcode Load or execute via "APC technic"
An advanced tool for bypassing EDR (Endpoint Detection and Response) systems and antivirus software by dynamically generating and injecting shellcode
Shellcode injection or execution via AddressOfEntryPoint hijack.
LotL-Watcher is a lightweight security monitoring tool designed to detect and mitigate "Living-off-the-Land" attacks. Instead of relying on traditional file signatures, this tool monitors the behavior of trusted Windows binaries (like certutil, powershell, wmic, mshta).
M-Rans | Ransomware From M-Packs malware Packages, "For security purposes"
This repository is a mirror of https://gitlab.com/sequence/core
A lightweight, asynchronous User-Mode Endpoint Detection and Response (EDR) architecture prototype using ETW (Event Tracing for Windows) and a Python C2 telemetry server. Built to demonstrate endpoint visibility without custom kernel drivers.
Sovereign Industrial Windows EDR + UEBA Suite for ZeroUniverse: Kernel ETW Telemetry, In-Memory Process Graph, MITRE ATT&CK Rules, Statistical UEBA, and ZeroSecurity Primitives.
Arcane EDR is a lightweight Windows service for making unattended agent workstations safer while still allowing fast, bleeding-edge work.
High-Performance Open-Source Windows EDR + UEBA in C#/.NET 8: Behavior Graph, Process Tree Lineage, Sigma Rules, Z-Score Anomaly & Explainable Risk Scoring
Windows process, memory and network monitor with behavioural intrusion detection. Fully offline: no telemetry, no accounts, no network calls. Arabic interface.
A lightweight Windows Endpoint Detection & Response (EDR) system with WMI process monitoring, VirusTotal integration, and real-time host isolation.
To associate your repository with the edr topic, visit your repo's landing page and select "manage topics."