
PE-Obfuscator
PE obfuscator with Evasion in mind

PE obfuscator with Evasion in mind

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

Reflective PE packer.

PowerSploit - A PowerShell Post-Exploitation Framework

Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

PE loader with various shellcode injection techniques

BOF to run PE in Cobalt Strike Beacon without console creation

Local PE injection technique using hardware breakpoints and vectored exception handling to manipulate DLL loading and execute arbitrary payloads, as…

A minimal PE mapper that loads DLLs straight from memory and calls into a clean plugin interface, no LoadLibrary needed.

Implementing Ghostly-Hollowing using tampered syscalls for remote PE injection

Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

Dynamically invoke arbitrary unmanaged code

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!