{"id":25405956,"url":"https://github.com/yinsel/BypassAV","last_synced_at":"2025-10-31T01:31:46.914Z","repository":{"id":251467937,"uuid":"837507424","full_name":"yinsel/BypassAV","owner":"yinsel","description":"一款基于PE Patch技术的后渗透免杀工具，支持32位和64位","archived":false,"fork":false,"pushed_at":"2025-01-11T07:08:03.000Z","size":3805,"stargazers_count":265,"open_issues_count":0,"forks_count":26,"subscribers_count":3,"default_branch":"main","last_synced_at":"2025-01-11T08:18:07.833Z","etag":null,"topics":["bypass-av"],"latest_commit_sha":null,"homepage":"","language":"C++","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/yinsel.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2024-08-03T07:17:36.000Z","updated_at":"2025-01-11T08:12:37.000Z","dependencies_parsed_at":"2024-08-03T08:46:23.069Z","dependency_job_id":"b772559a-9dcf-4b62-a0b4-ff4d8b8e12e2","html_url":"https://github.com/yinsel/BypassAV","commit_stats":null,"previous_names":["yinsel/bypassav"],"tags_count":6,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yinsel%2FBypassAV","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yinsel%2FBypassAV/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yinsel%2FBypassAV/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yinsel%2FBypassAV/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/yinsel","download_url":"https://codeload.github.com/yinsel/BypassAV/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":239088378,"owners_count":19579434,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["bypass-av"],"created_at":"2025-02-16T05:03:31.151Z","updated_at":"2025-10-31T01:31:46.908Z","avatar_url":"https://github.com/yinsel.png","language":"C++","funding_links":[],"categories":["C++","红队\u0026渗透测试"],"sub_categories":[],"readme":"# BypassAV\n\n\u003cp\u003e\n\u003cimg src=\"https://img.shields.io/github/stars/yinsel/BypassAV?style=flat\" alt=\"GitHub Repo stars\"/\u003e\n\u003cimg src=\"https://img.shields.io/github/downloads/yinsel/BypassAV/total?style=flat\" alt=\"GitHub Downloads (all assets, all releases)\"/\u003e\n\u003cimg alt=\"GitHub Release\" src=\"https://img.shields.io/github/release/yinsel/BypassAV\"/\u003e\n\u003cp\u003e\n\n对各种白文件进行Patch，以便绕过AV（基础shellcode已开源，可以根据需求自行修改），也可使用[此模板](https://github.com/yinsel/ShellcodeDev)进行编写，实现了从文件加载`shellcode`，无任何加密，请使用[Sgn](https://github.com/EgeBalci/sgn)项目对`shellcode`进行编码。\n\n**360 环境下的webshell，默认情况下无法通过常规的命令行执行exe，会出现拒绝访问，与该项目本身的免杀无关，属于行为监控。**\n\n## 使用方法\n\n使用仓库中`EXEToShellcode`或者[donut](https://github.com/TheWover/donut)、[pe_to_shellcode](https://github.com/hasherezade/pe_to_shellcode)等工具将`fscan`、`mimikatz`等后渗透工具转为`shellcode`或者在Webshell场景下需要上线C2的`shellcode`并使用[Sgn](https://github.com/EgeBalci/sgn)进行编码以规避查杀，并重命名为`bin`，直接运行即可。\n\n**注：请确保你转换后的shellcode能正常运行。**\n\n本工具仅限用于合法的渗透测试，请勿用于违法行为，因本工具造成的任何损失由使用者自行承担。\n\n## 更新记录\n**2025.3.5---v1.6 添加间接syscall**\n\n**2025.1.11---v1.5 Bypass AMSI**\n\n**2024.10.18---v1.4 更换x64位白文件**\n\n**2024.08.14---v1.3 新增32位白文件**\n\n**2024.08.07---v1.2 更换白文件发布至release**\n\n**2024.08.03---v1.1 使用sgn编码shellcode**\n\n**2024.08.03---v1.0 初次发布**\n\n**如有问题，可直接在issue提问。**\n\n## 杀软测试（2024.08.05）\n360：\n\n![image](https://github.com/user-attachments/assets/1d5bf6be-cdb7-4bb8-9745-6cd8db46eca7)\n\n火绒：\n\n![image](https://github.com/user-attachments/assets/21705624-785b-4465-a3e6-02279d9f3cfc)\n\nWindows Defender：\n\n![image](https://github.com/user-attachments/assets/cdff7863-e1c3-49b2-8e3e-b311034b011d)\n\n卡巴斯基企业版：\n\n![image](https://github.com/user-attachments/assets/df17ab1a-8048-47f0-954b-e245ab62b62f)\n\n\n## 参考链接\n\n技术链接：\n\n[https://xz.aliyun.com/t/15081](https://xz.aliyun.com/t/15081)\n\n[https://xz.aliyun.com/t/15096](https://xz.aliyun.com/t/15096)\n\nshellcode开发：\n\n[https://github.com/yinsel/ShellcodeDev](https://github.com/yinsel/ShellcodeDev)\n\n检测方式：\n\n[https://key08.com/index.php/2024/08/03/1949.html](https://key08.com/index.php/2024/08/03/1949.html)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fyinsel%2FBypassAV","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fyinsel%2FBypassAV","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fyinsel%2FBypassAV/lists"}