
sRDI
Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

Spoof file icons and extensions in Windows

AV/EDR evasion via direct system calls.

This repo contains some Amsi Bypass methods i found on different Blog Posts.

Azure Function that validates and relays Cobalt Strike beacon traffic using malleable C2 profiles, redirecting invalid requests to a decoy site and…

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

LSTAR - CobaltStrike Translated to EN

Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles…

Trojanize your payload - WinRAR (SFX) automatization - under Linux distros

A shellcode function to encrypt a running process image when sleeping.

"Two-Face" Rust binary on Linux

CS_SleepMask

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Polymorphic binary encoder for offensive security payloads. Encodes shellcode with LFSR-based feedback loop, garbage instruction injection, and…

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver