Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
byvalver — takes shellcode bad-bytes and banishes them, returning cleaned shellcode with preserved functionalities | Kitploit
Tools/GitHubGitHub/umpolungfish/byvalver
ExploitationShellcodeMalware AnalysisPenetration TestingBinary AnalysisMachine LearningRed TeamingShellcode GenerationPayload Development
GitHubumpolungfish/byvalver

byvalver

takes shellcode bad-bytes and banishes them, returning cleaned shellcode with preserved functionalities

639697 months agoReviewed by Kitploit
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

byvalver (·𐑚𐑲𐑝𐑨𐑤𐑝𐑼)

THE SHELLCODE BAD-BYTE BANISHER

byvalver banishes bad-bytes with extreme prejudice
C++ SHELLCODE SCRUBBING CROSS-PLATFORM ARCHITECTURES BUILD CLEAN GitHub stars GitHub forks SPONSOR ON gitHub SUPPORT ON ko-fi

Overview • Quick Start • Interactive TUI • Targeted Bad-Byte Elimination • Bad-Byte Profiles • Features • Architecture • System Requirements • Dependencies • Building • Installation • Usage • Obfuscation Strategies • Denullification Strategies • ML Training • Agent Menagerie • Development • Troubleshooting • License


Table of Contents

  • Overview
  • Quick-Start
    • Installation
    • Basic Usage
    • Verification
    • Cross-Architecture Support
    • Batch Processing
  • Interactive TUI
  • Targeted Bad-Byte Banishment
  • Bad-Byte Profiles
  • Features
    • Advanced Transformation Engine
    • Performance Metrics
    • Obfuscation Layer
    • ML-Powered Strategy Selection
    • Output Options
    • Verification Suite
  • Architecture
  • System Requirements
  • Dependencies
  • Building
  • Installation
  • Usage
  • Obfuscation Strategies
  • Denullification Strategies
  • ML Training & Validation
  • Agent Menagerie
  • Development
  • Documentation
  • Troubleshooting
  • License

Overview

byvalver is a CLI tool built in C for automatically eliminating (or "banishing") bad-bytes from x86/x64/ARM/ARM64 shellcode while maintaining complete functional equivalence

NEW in v4.0: Cross-Architecture Support

ArchitectureMaturityStrategiesNotes
x86 (32-bit Intel/AMD)Stable v4.2150+Production-tested, full coverage
x64 (64-bit Intel/AMD)Stable v4.2150+Default architecture, production-tested
ARM (32-bit)Experimental v0.17 coreLimited testing, core instructions only
ARM64 (AArch64)Experimental v0.1BasicFramework ready, minimal strategies
  • Automatic Capstone mode selection via --arch flag

v4.0.1 Bug Fixes:

  • Fixed ARM SUB instruction encoding (correct opcode 0x2 with I=1 bit)
  • Fixed ARM64 strategy can_handle logic for pass-through strategies
  • Added experimental warnings when ARM/ARM64 architecture is selected
  • Added architecture mismatch detection heuristics
  • Improved code organization (includes moved to file scope)

NEW in v4.2: Enhanced x64 Support

  • x86/x64 Strategy Compatibility Layer: 128+ x86 strategies now work on x64 shellcode
  • 5 New x64-Specific Strategy Files: MOVABS, SBB, TEST, SSE Memory, LEA Displacement
  • Extended Register Encoding: Full R8-R15 support with proper REX prefix handling
  • REX Prefix Utilities: is_64bit_register(), is_extended_register(), build_rex_prefix()
  • Resolves 100% failure rate on x64-only shellcode samples

The tool uses the Capstone disassembly framework to analyze instructions and applies over 175+ ranked transformation strategies to replace bad-byte-containing code with equivalent alternatives

The generic bad-byte banishment framework provides 2x usage modes:

  1. Direct specification: The --bad-bytes option allows specification of arbitrary bytes to banish (e.g., --bad-bytes "00,0a,0d" for newline-safe shellcode)
  2. Profile-based: The --profile option uses pre-configured bad-byte sets for common exploit scenarios (e.g., --profile http-newline, --profile sql-injection, --profile alphanumeric-only)

Supports Windows, Linux, and macOS

CORE TECH:

  • Pure C implementation for efficiency and low-level control
  • Capstone for precise disassembly
  • NASM for generating decoder stubs
  • Modular strategy pattern for extensible transformations (153+ strategy implementations)
  • Neural network integration for intelligent strategy selection
  • Biphasic processing: Obfuscation followed by denullification

[!NOTE] Null-byte elimination (--bad-bytes "00" or default): WELL-TESTED / Generic bad-byte elimination (--bad-bytes "00,0a,0d" etc.): NEWLY IMPLEMENTED

BAD-BYTE BANISHMENT IN ACTION

bad-byte banishment in action

QUICK-START

Get started with byvalver in minutes:

INSTALLATION

OPTION 1: FROM GITHUB (RECOMMENDED)

curl -sSL https://raw.githubusercontent.com/umpolungfish/byvalver/main/install.sh | bash

OPTION 2: BUILD FROM SOURCE

git clone https://github.com/umpolungfish/byvalver.git
cd byvalver
make
sudo make install
sudo make install-man  # Install man page

Basic Usage

banish NULL BYTES (DEFAULT):

byvalver input.bin output.bin

USING BAD-BYTE PROFILES:

# HTTP contexts (removes null, newline, carriage return)
byvalver --profile http-newline input.bin output.bin

# SQL injection contexts
byvalver --profile sql-injection input.bin output.bin

# Alphanumeric-only shellcode (most restrictive)
byvalver --profile alphanumeric-only input.bin output.bin

MANUAL BAD-BYTE SPECIFICATION:

# banish null bytes and newlines
byvalver --bad-bytes "00,0a,0d" input.bin output.bin

ADVANCED FEATURES:

# Add obfuscation layer before denullification
byvalver --biphasic input.bin output.bin

# Enable ML-powered strategy selection
byvalver --ml input.bin output.bin
Download Tool