
CallObfuscator
Obfuscate specific windows apis with different apis

Obfuscate specific windows apis with different apis

Spoof file icons and extensions in Windows

Super UEFIinSecureBoot Disk: Boot any OS or .efi file without disabling UEFI Secure Boot

Runtime tracer for Node.js malware analysis that hooks core modules, logs calls, spoofs anti-analysis checks, and captures file writes and HTTP…

C++ tool that patches Windows API calls to bypass sandbox RAM size checks, enabling malware to evade detection in isolated analysis environments.

PowerShell tool for red teamers that clears execution evidence by stopping event logging, removing file and registry artifacts, and saving timestamps…

AppLocker-Based EDR Neutralization

Tunnel TCP connections through a file

Red Team tool for covert file exfiltration via Bluetooth audio transmission, encoding binary data into FLAC signals to bypass EDR, XDR, and DLP…

Exploit for CVE-2023-23397 Outlook NTLM hash leak via malicious calendar invitations. Includes PowerShell weaponization, Responder integration, and…

Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)

Zip file format fuzzer and multi-tool.

A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.

Mutates signed Windows binaries to retain valid catalog signatures while changing file hashes, bypassing hash-based endpoint blocks and exposing…

A Runtime Crypter in C for Linux ELF binaries.

Convert Cobalt Strike profiles to modrewrite scripts

Remove API hooks from a Beacon process.

Remove API hooks from a Beacon process.