
F31
Tool for hiding Kali Linux on the network

Tool for hiding Kali Linux on the network

Reverse-engineered Easy Anti-Cheat kernel driver bypass that intercepts memory allocation to suppress violation packets, with report decryption…

Cross-platform syscall-powered implant & C2 — direct syscalls (Win), raw syscalls (Linux), HTTPS/DNS/ICMP channels. No winapi layer.

Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

Red team tool for EDR evasion: dynamically resolves syscall IDs, patches ntdll stubs, unhooks IAT hooks, and lists hooked APIs from major EDR vendors.

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

collection of apis used in malware development

Hands-on red-team obfuscation workshop teaching AMSI bypass, ETW evasion, and payload obfuscation with PowerShell, Visual Basic, and C# to evade…

PoCs and tools for investigation of Windows process execution techniques


List of Awesome CobaltStrike Resources

Tools and PoCs for Windows syscall investigation.