
ProtectMyTooling
Multi-Packer wrapper letting us daisy-chain various packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts watermarking,…

Multi-Packer wrapper letting us daisy-chain various packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts watermarking,…

Polymorphic encryptor that transforms shellcode, PE, and COFF files into obfuscated, position-independent payloads with RC4 and random block cipher…

Malicious HTTP traffic explorer

evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)

Sickle - Payload Development Kit

Nim-based assembly packer and shellcode loader for opsec & profit

Obfusk8: lightweight Obfuscation library based on C++17 / Header Only for windows binaries

Polymorphic C2 profile generator for Cobalt Strike that automates creation of evasive beacon configurations with randomized options for HTTP, DNS,…

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners…

Patch Binaries via MITM: BackdoorFactory + mitmProxy.

Cobalt Strike UDRL for memory scanner evasion.

Cooolis-ms是一个包含了Metasploit Payload Loader、Cobalt Strike External C2 Loader、Reflective DLL injection的代码执行工具,它的定位在于能够在静态查杀上规避一些我们将要执行且含有特征的代码,帮助红队人员更方便快…

THorse is a RAT (Remote Administrator Trojan) Generator for Windows/Linux systems written in Python 3.

Automated ROP chain builder that extracts and analyzes gadgets from binaries using semantic queries, supporting X86/X64 architectures with a Python…

RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.

ROP-based sleep obfuscation to evade memory scanners

Public repository for improvements to the EXTRABACON exploit

Script to generate malicious debian packages (debain trojans).