More
More
-
-
Agent-Loader Public
Forked from vvswift/Agent-LoaderModular C2 loader featuring dynamic function encryption, in-memory payload support, and a covert DoH command channel, configurable via a Python builder and a Node.js web panel.
C UpdatedMay 11, 2025 -
ARM64-ReflectiveDLLInjection Public
Forked from xaitax/ARM64-ReflectiveDLLInjectionA Proof-of-Concept implementation of Reflective DLL Injection (RDI) specifically for Windows on ARM64. Demonstrates PEB access via the x18 register and manual DLL mapping.
C UpdatedMay 30, 2025 -
BOAZ_beta Public
Forked from thomasxm/BOAZ_betaMultilayered AV/EDR Evasion Framework
C++ GNU General Public License v3.0 UpdatedJan 11, 2025 -
-
C2Implant Public
Forked from maxDcb/C2ImplantWindows C++ Implant for Exploration C2
C++ MIT License UpdatedFeb 14, 2025 -
C2TeamServer Public
Forked from maxDcb/C2TeamServerTeamServer and Client of Exploration Command and Control Framework
Python MIT License UpdatedFeb 18, 2025 -
Caro-Kann Public
Forked from S3cur3Th1sSh1t/Caro-KannEncrypted shellcode Injection to avoid Kernel triggered memory scans
C UpdatedSep 12, 2023 -
ChaiLdr Public
Forked from Cipher7/ChaiLdrAV bypass while you sip your Chai!
C MIT License UpdatedMay 17, 2024 -
-
COFF-Loader Public
Forked from Ap3x/COFF-LoaderA reimplementation of Cobalt Strike's Beacon Object File (BOF) Loader
C++ MIT License UpdatedDec 16, 2023 -
concealed_code_execution Public
Forked from huntandhackett/concealed_code_executionTools and technical write-ups describing attacking techniques that rely on concealing code execution on Windows
C MIT License UpdatedAug 12, 2022 -
-
hookchain Public
Forked from helviojunior/hookchainHookChain: A new perspective for Bypassing EDR Solutions
C UpdatedJan 5, 2025 -
lib-nosa Public
Forked from ViperXSecurity/lib-nosalib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.
C Apache License 2.0 UpdatedSep 8, 2024 -
MicroBackdoor Public
Forked from Cr4sh/MicroBackdoorSmall and convenient C2 tool for Windows targets. [ Русский -- значит нахуй! ]
C++ GNU General Public License v3.0 UpdatedMar 8, 2022 -
nimplant-beacon-position-independent-c-code Public
Forked from tijme/nimplant-beacon-position-independent-c-codeA truly Position Independent Code (PIC) NimPlant C2 beacon written in C, without reflective loading.
C GNU General Public License v2.0 UpdatedFeb 11, 2025 -
ntlmssp Public
Forked from EddieIvan01/ntlmsspWindows NTLMSSP library
Go Mozilla Public License 2.0 UpdatedOct 13, 2020 -
process-cloning Public
Forked from huntandhackett/process-cloningThe Definitive Guide To Process Cloning on Windows
C MIT License UpdatedJan 3, 2024 -
ProtectedUtils Public
Forked from sodinokibi/ProtectedUtilsCreatively retrieve module base, teb, peb or function base
C++ UpdatedJun 14, 2024 -
-
proxyres Public
Forked from snxd/proxyresCross-platform proxy resolution library written in C.
C MIT License UpdatedJan 12, 2025 -
RemoteFunctionPatcher Public
Forked from S12cybersecurity/RemoteFunctionPatcherPatch (block) whatever function you want in a remote process. Adding a ret instruction at the first memory address of this function, the target function will be exited automatically all the times c…
C++ UpdatedJul 11, 2024 -
RflDllOb Public
Forked from oldboy21/RflDllObReflective DLL Injection Made Bella
C GNU General Public License v2.0 UpdatedJan 6, 2025 -
rust_api_demo Public
Forked from Teach2Breach/rust_api_demovarious methods of making API calls
Rust MIT License UpdatedFeb 1, 2025 -
SentinelBruh Public
Forked from mannyfred/SentinelBruhDirty PoC on how to abuse S1's VEH for Vectored Syscalls and Local Execution
C GNU General Public License v2.0 UpdatedJul 14, 2024 -
SentinelGone Public
Forked from mannyfred/SentinelGonePrime a process for injection when S1 is present
C MIT License UpdatedJan 23, 2025 -
shellc_encoder Public
Forked from hasherezade/shellc_encoderStandalone Metasploit-like XOR encoder for shellcode
C UpdatedMay 12, 2024 -
VMAware Public
Forked from kernelwernel/VMAwareVM detection library and tool
C++ MIT License UpdatedJan 25, 2025 -
WindowsAP1 Public
Forked from DebugPrivilege/WindowsAP1Code samples that serve as references for Windows API functions
UpdatedMay 28, 2024