
MrKaplan
PowerShell tool for red teamers that clears execution evidence by stopping event logging, removing file and registry artifacts, and saving timestamps…

PowerShell tool for red teamers that clears execution evidence by stopping event logging, removing file and registry artifacts, and saving timestamps…

ICMP, DNS, and NTP tunneling tool for bypassing censorship, with HMAC integrity protection and MSS clamping for efficient web sessions over…

C++ tool for detecting AnyRun sandbox environments, enabling malware to evade dynamic analysis and automated sandboxing systems.

Nim-based encryption tool for obfuscating shellcode and payloads for evading Windows Defender.

Killer is a super simple tool designed to bypass AV/EDR security tools using various evasive techniques and used by Patchwork group.

A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.

Kernel-level tool to disable Sysmon and Windows Event Logging via driver-based hook injection, enabling stealthy post-exploitation operations on…

yet another AV killer tool using BYOVD

A high-performance port spoofing tool built in Rust. Confuse port scanners with dynamic service emulation across all ports. Features customizable…

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

Obfuscate specific windows apis with different apis

👁🗨 This script will simulate fake processes of analysis sandbox/VM software that some malware will try to avoid.

Monitors Asterisk authentication logs and automatically bans IPs with repeated failed login attempts using iptables, with configurable thresholds and…

CVE-2025-55182-scanner with 2 different method

Ability to detect suspicious activity such as (WEP/WPA/WPS) attack by sniffing the air for wireless packets.

THorse is a RAT (Remote Administrator Trojan) Generator for Windows/Linux systems written in Python 3.

C++ tool that patches Windows API calls to bypass sandbox RAM size checks, enabling malware to evade detection in isolated analysis environments.