
SharpZipRunner
Executes position independent shellcode from an encrypted zip

Executes position independent shellcode from an encrypted zip

yet another AV killer tool using BYOVD

Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

C# implementations of shellcode injection techniques including classic injection, thread hijacking, process hollowing, and atom bombing, using…

Python AV Evasion Tools

Activation Context Hijacking Evasion Tool

PE obfuscator with Evasion in mind

Rust crate for ghost-frame call-stack spoofing, runtime indirect syscalls, and APC injection on Windows x64. Provides SSN resolution, JIT stub…

A Cobalt Strike memory evasion loader for redteamers

PowerShell-based Active Directory enumeration tool for gathering network configuration, domain objects, user sessions, share permissions, and…

Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.



This is a webshell open source project

Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors

A modern 32/64-bit position independent implant template