0xHossam / Killer

Killer tool is designed to bypass AV/EDR security tools using various evasive techniques.
722 stars 109 forks source link

EDR detected #7

Closed Jigsaw855 closed 1 year ago

Jigsaw855 commented 1 year ago

hi my friend I have 2 questions about your tools 1 I tested your tools on crowed strike falcon and it detected your tools , do you have idea about bypass it ?

  1. I created a payload and copy its export in shellcode-xor.py and get this error "IndentationError: unexpected indent"
  2. how shall I run killer correctly ? please explain me
kalinavladd commented 1 year ago

I can't compile that tool too) I have any errors, syntax errors, etc. But authors articles are good) And, antiscan.me bad tool, because I made 2 malware, and windows defender detect file (after 2 days), and now I send this file to antiscan.me and I have result 0/26) lol

0xHossam commented 1 year ago

Hey all, the first problem that the EDR detected it that's because every thing will be detected while it's public also you shouldn't upload it to crowed strike falcon because that let another anti viruses detect it more but any way I will put updates every time to still FUD!

@kalinavladd If you can't compile it that's mean that you don't understand c++, use visual studio compiler to compile it!

kalinavladd commented 1 year ago

@0xHossam Thanks, I'll try. I'm just learning how to develop malware. In the future, I will try to implement your techniques indicated in your articles on rust. Could you recommend a book or materials (preferably fresh and new) on malware development?