
Empire
Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Obex – Blocking unwanted DLLs in user mode

Implementing Ghostly-Hollowing using tampered syscalls for remote PE injection

IPSpinner works as a local proxy that redirects requests through external services.

Super UEFIinSecureBoot Disk: Boot any OS or .efi file without disabling UEFI Secure Boot

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.


Tunna is a set of tools which will wrap and tunnel any TCP communication over HTTP. It can be used to bypass network restrictions in fully firewalled…

DejaVU - Open Source Deception Framework

Adversary Emulation Framework

WePWNise generates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and…

Convert shellcode into :sparkles: different :sparkles: formats!

A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.

Go shellcode loader that combines multiple evasion techniques

Killer is a super simple tool designed to bypass AV/EDR security tools using various evasive techniques and used by Patchwork group.

A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation

Python-based crypter that encrypts source code with AES-256 and Base64, evades VM detection via registry, process, and MAC checks, and executes…

SysWhispers on Steroids - AV/EDR evasion via direct system calls.