Stars
Cobalt Strike BOF for evasive .NET assembly execution
Proof of Concept (PoC) implant for creating custom Cobalt Strike Beacons
Fritter is a heavily modified fork of TheWover and Odzhan's Donut shellcode generator.
Kernel-Enforced Install-Time Policies (KEIP): An eBPF/LSM based security tool that detects and blocks malicious network activity during pip install.Kernel-Enforced Install-Time Policies (KEIP): An …
Crystal Palace RDLL loader for Adaptix C2 with Ekko sleep obfuscation, IAT hooking via PICO, and per-section permission restoration
This is an implementation of a native-code Meterpreter, designed for portability, embeddability, and low resource utilization.
Ryūjin Protector - Is a Intel Arch - BIN2BIN - PE Obfuscation/Protection/DRM tool
Reflective DLL loading of your favorite Golang program
TrevorC2 is a legitimate website (browsable) that tunnels client/server communications for covert command execution.
UDC2 implementation that provides an ICMP C2 channel
BOF to run PE in Cobalt Strike Beacon without console creation
Agent for AdaptixC2 with focus in evasion, capability and malleable.
Obfusheader.h is a portable header file for C++14 compile-time obfuscation.
Using call gadgets to break the call stack signature used by Elastic on proxying a module load. Provided as a Crystal Palace shared library. Format inspired by @rasta-mouse's LibTP.
Exposing CharmingKitten's malicious activity for IRGC-IO Counterintelligence division (1500)
Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing them inside images or videos. A lightweight loader …
A free but powerful Windows kernel research tool.
A meterpreter extension for applying hooks to avoid windows defender memory scans
Execute unmanaged Windows executables in CobaltStrike Beacons
Framework for Automating Fuzzable Target Discovery with Static Analysis.
Golang PoC that sandboxes Defender (or other PPL) by setting its token integrity to Untrusted.
Azazel is a userland rootkit based off of the original LD_PRELOAD technique from Jynx rootkit. It is more robust and has additional features, and focuses heavily around anti-debugging and anti-dete…