Skip to content
View xkroot's full-sized avatar

Block or report xkroot

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

C 207 35 Updated Jul 8, 2026
C 16 5 Updated May 1, 2025

Cobalt Strike BOF for evasive .NET assembly execution

C 323 37 Updated Mar 31, 2025

Proof of Concept (PoC) implant for creating custom Cobalt Strike Beacons

C 217 40 Updated Feb 11, 2026

Fritter is a heavily modified fork of TheWover and Odzhan's Donut shellcode generator.

C 246 40 Updated Aug 4, 2026

Kernel-Enforced Install-Time Policies (KEIP): An eBPF/LSM based security tool that detects and blocks malicious network activity during pip install.Kernel-Enforced Install-Time Policies (KEIP): An …

Python 63 7 Updated Jun 1, 2026

Crystal Palace RDLL loader for Adaptix C2 with Ekko sleep obfuscation, IAT hooking via PICO, and per-section permission restoration

C++ 160 19 Updated Jun 5, 2026

Official git repo for iodine dns tunnel

C 7,943 597 Updated Sep 4, 2025

This is an implementation of a native-code Meterpreter, designed for portability, embeddability, and low resource utilization.

C 491 135 Updated Jul 29, 2026

Ryūjin Protector - Is a Intel Arch - BIN2BIN - PE Obfuscation/Protection/DRM tool

C++ 338 49 Updated Nov 20, 2025

Evasion by machine code de-optimization.

Rust 431 30 Updated Jul 22, 2024

Simple Linux Rat ?

C++ 22 4 Updated Dec 21, 2025

Reflective DLL loading of your favorite Golang program

C 172 20 Updated Jan 27, 2020

TCP Port Redirection Utility

C 789 121 Updated Jan 31, 2023

TrevorC2 is a legitimate website (browsable) that tunnels client/server communications for covert command execution.

C 1,343 282 Updated Jan 31, 2022

UDC2 implementation that provides an ICMP C2 channel

Python 126 18 Updated Nov 24, 2025

BOF to run PE in Cobalt Strike Beacon without console creation

C++ 200 25 Updated Nov 23, 2025

Agent for AdaptixC2 with focus in evasion, capability and malleable.

C 226 54 Updated Apr 26, 2026

Obfusheader.h is a portable header file for C++14 compile-time obfuscation.

C++ 1,014 118 Updated Aug 19, 2024
Python 237 24 Updated Jun 10, 2025

Using call gadgets to break the call stack signature used by Elastic on proxying a module load. Provided as a Crystal Palace shared library. Format inspired by @rasta-mouse's LibTP.

C 88 6 Updated Nov 6, 2025

Exposing CharmingKitten's malicious activity for IRGC-IO Counterintelligence division (1500)

C# 432 100 Updated Oct 27, 2025

Sliver agent rewritten in C++

C++ 49 8 Updated Sep 4, 2024

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing them inside images or videos. A lightweight loader …

C++ 171 37 Updated Feb 2, 2026

A free but powerful Windows kernel research tool.

2,711 580 Updated Dec 14, 2025

A meterpreter extension for applying hooks to avoid windows defender memory scans

C 251 41 Updated Aug 13, 2020

Execute unmanaged Windows executables in CobaltStrike Beacons

C 723 103 Updated Mar 4, 2023

Framework for Automating Fuzzable Target Discovery with Static Analysis.

Python 549 59 Updated Jun 11, 2026
Next