Skip to content

M4rdc0re/TartarusHall

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

17 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

TartarusHall: EDR Evasion

Features

  • API Hashing using CRC32
  • Indirect syscalls, utilizing HellHall with ROP gadgets (for the unhooking part).
  • DLL unhooking from \KnwonDlls\ directory, with no RWX sections.
  • RC4 payload encryption
  • Brute forcing the decryption key
  • No CRT library imports

Usage

  • Hasher to calculate API hashes
  • PayloadBuilder to generate a encrypted key and encrypt the payload

Credits

Disclaimer

This repository is created for educational purposes only. Any legal responsibility belongs to the person or organization that uses it.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published