
sliver
Adversary Emulation Framework

Adversary Emulation Framework

DejaVU - Open Source Deception Framework

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Tunna is a set of tools which will wrap and tunnel any TCP communication over HTTP. It can be used to bypass network restrictions in fully firewalled…

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.


Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

Convert shellcode into :sparkles: different :sparkles: formats!

Killer is a super simple tool designed to bypass AV/EDR security tools using various evasive techniques and used by Patchwork group.

Go shellcode loader that combines multiple evasion techniques

Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)

WePWNise generates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and…

Implementing Ghostly-Hollowing using tampered syscalls for remote PE injection

IPSpinner works as a local proxy that redirects requests through external services.

Python-based crypter that encrypts source code with AES-256 and Base64, evades VM detection via registry, process, and MAC checks, and executes…

A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation

A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.