2023-07-06 20:40:15 +02:00
2023-07-06 20:40:15 +02:00

NimBlackout

License Nim Version

Note

: This project is for educational purposes only. The use of this code for any malicious activity is strictly prohibited. I am not responsible for any misuse of this software.

NimBlackout is an adaptation of the @Blackout project originally developed in C++ by @ZeroMemoryEx, which consists of removing AV/EDRs using the gmer (BYOVD) driver.

The main reason for this project was to understand how BYOVD attacks work, and then to provide a valid PoC developed in Nim.

All credit must goes to the original author @ZeroMemoryEx.

Usage

  • Put Blackout.sys driver into current directory

  • Launch NimBlackout

    NimBlackout.exe <process name>
    

    In order to prevent restarting process (like MsMpEng.exe), keep the program running.

S
Description
Automated archival mirror of github.com/Helixo32/NimBlackout
Readme
749 KiB
Languages
Nim 100%