
azureOutlookC2
Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North…

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North…

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Nim-based encryption tool for obfuscating shellcode and payloads for evading Windows Defender.

Freeze.rs is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls written in RUST

Killer is a super simple tool designed to bypass AV/EDR security tools using various evasive techniques and used by Patchwork group.

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs

A unique technique to execute binaries from a password protected zip

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

BOF combination of KillDefender and Backstab

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

EDRSandblast-GodFault

.NET, PE, & Raw Shellcode Packer/Loader Written in Nim

Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

Full-spectrum Linux adversary simulation platform with kernel-level stealth, C2 beaconing, privilege escalation, credential harvesting, lateral…