
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis
Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Converts a EXE into DLL

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs

C/C++ source obfuscator for antivirus bypass

Sickle - Payload Development Kit

Go-based Java serialization protocol analyzer that parses, dumps, and generates deserialization payloads with ysoserial gadget support and a library…

Run Beacon Object Files (BOFs) outside Cobalt Strike by parsing 64-bit COFF object files, with Beacon-compatible argument generation and helper…

metame is a metamorphic code engine for arbitrary executables

Excel Macro Document Reader/Writer for Red Teamers & Analysts

Python AV Evasion Tools

Simulates the Windows PE loader to identify DLL hijacking vulnerabilities, generates weaponized DLLs with shellcode payloads, and detects UAC…

PE loader with various shellcode injection techniques

🗜️ A packer for Windows x86 executable files written in C and Intel x86 Assembly. The new file after packing can obstruct reverse…

Pure Rust x86 hardware emulator and Windows process simulator for malware analysis, shellcode emulation, and payload unpacking. Supports 32/64-bit PE…

Generate a proxy dll for arbitrary dll

An architecture-agnostic ELF file flattener for shellcode

Dynamically extracts fresh syscall stubs from ntdll.dll to evade signature-based detection, with a shellcode execution template for Nim-based…

Lnk crafting and research tools