
hidden
🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

Collection of various malicious functionality to aid in malware development

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

🦫 | GoRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team, with a specific focus on…

THorse is a RAT (Remote Administrator Trojan) Generator for Windows/Linux systems written in Python 3.

ARM64 ELF Virtual Machine Protection System

Generates anti-copy malware launchers using Process Ghosting to bypass AV/EDR signature scanning and prevent automatic sample submission. Supports…

Redirects EDR working folders using a Bind Filter (bindflt.sys) to bypass endpoint detection, corrupt EDR services, or replace with…

InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution

Fully undetected grabber (grabs wallets, passwords, cookies, modifies discord client etc.)

PolyEngine is an evasive PE packer designed for CTF challenges and low-level Windows security education. It focuses on bypassing EDR and AV…

Randomly changes Win32/64 PE Files for 'safer' uploading to malware and sandbox sites.

Permanently disable EDRs as local admin

Creation of multiple Malware tools consisting of evasion, enumeration and exploitation

This is a quick script installation for resilient redirector using nginx reverse proxy and letsencrypt compatible with some popular Post-Ex Tools…

PostShell - Post Exploitation Bind/Backconnect Shell

🛡️ Open-source binary protection toolkit for Windows PE. Nanomite, VM protection, anti-debug, and more.