
DInvoke_rs
Dynamically invoke arbitrary unmanaged code

Dynamically invoke arbitrary unmanaged code

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

A tool to detect and crash Cuckoo Sandbox

Nim Library for Offensive Security Development

Randomly changes Win32/64 PE Files for 'safer' uploading to malware and sandbox sites.

Userland exec PoC to be used as attack vector technique

C++ tool that patches Windows API calls to bypass sandbox RAM size checks, enabling malware to evade detection in isolated analysis environments.

Platform independent peCloak fork based on Capstone

BYOVD: Use 360 WFP driver to block EDR/XDR network connection.

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

Linux process identity cloaking tool that spoofs comm, argv, cmdline, environ, exe path, and VMAs via an 11-phase prctl pipeline to impersonate…