Skip to content

This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context of download cradle detections.

Notifications You must be signed in to change notification settings

l4ckyguy/Payload-Download-Cradles

 
 

Repository files navigation

Payload Download Cradles

This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context of download cradle detections. Notice, removing or obfuscating signatures from your download cradle is only one piece of the puzzle to bypass an AV/EPP/EDR. Depending on the respective product you have to modify your payload which should be downloaded by the cradle to bypass API-Hooking, Callbacks, AMSI etc.

For PowerShell obfuscation I used as usual the amazing tool Invoke Obufscation from Daniel Bohannon https://github.com/danielbohannon/Invoke-Obfuscation

About

This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR in context of download cradle detections.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Batchfile 51.6%
  • PowerShell 31.8%
  • HTML 9.8%
  • JavaScript 6.8%