
GTRS
Reverse shell tool that uses Google Translate as a proxy to send commands and exfiltrate data, evading network detection. Supports bash and Go…

Reverse shell tool that uses Google Translate as a proxy to send commands and exfiltrate data, evading network detection. Supports bash and Go…

A tool which bypasses AMSI (AntiMalware Scan Interface) and PowerShell CLM (Constrained Language Mode) and gives you a FullLanguage PowerShell…

A reverse shell with terminal support, data tunneling, and advanced pivoting capabilities.

Powershell reverse shell using HTTP/S protocol with AMSI bypass and Proxy Aware

Pure Python post-exploitation RAT for macOS with SSL/TLS encrypted reverse shell, automated data mining, iCloud token extraction, keychain…

Multi-protocol reverse shell toolkit with AMSI patching, RC4 encryption, and SilentTrinity C2 integration for red team operations. Supports TCP, UDP,…

Offensive Windows BYOVD tool exploiting ECHOAC anti-cheat driver for kernel read/write, removing EDR callbacks/ETW providers, and escalating…

PowerShell obfuscation tool that bypasses AMSI and antivirus detection using string substitution and variable concatenation to evade signatures for…

Red team tool for EDR evasion: dynamically resolves syscall IDs, patches ntdll stubs, unhooks IAT hooks, and lists hooked APIs from major EDR vendors.

A tool to detect and crash Cuckoo Sandbox

Automated nginx reverse proxy and DNS redirector setup for CobaltStrike and HTTP RATs, with automatic letsencrypt SSL certificate provisioning and…

C++ tool that patches Windows API calls to bypass sandbox RAM size checks, enabling malware to evade detection in isolated analysis environments.

ELF anti-reversing tool that overwrites section headers with nullbytes to prevent static analysis by disassemblers and debuggers, rendering functions…

Systematic discovery tool for kernel code paths that bypass LSM security guarantees via eBPF, io_uring, and mount API manipulation with zero audit…

Obfuscate specific windows apis with different apis

Tools and PoCs for Windows syscall investigation.

Converts arbitrary shellcode into ROP chains and patches them into 32-bit PE files for polymorphism and antivirus evasion. Supports multiple…

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.