
GhostDriver
yet another AV killer tool using BYOVD

yet another AV killer tool using BYOVD

PolyEngine is an evasive PE packer designed for CTF challenges and low-level Windows security education. It focuses on bypassing EDR and AV…

Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

A tool which creates a spoofed certificate of any online website and signs an Executable for AV Evasion. Works for both Windows and Linux

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

C# implementations of shellcode injection techniques including classic injection, thread hijacking, process hollowing, and atom bombing, using…

Python AV Evasion Tools

Activation Context Hijacking Evasion Tool

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

PE obfuscator with Evasion in mind

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…

Tools that trigger False Positive AV alerts

ELF binary section docking toolkit for stageless payload delivery, enabling in-field payload attachment, signature evasion, and static/dynamic…

golang script for bypass AV and work only in windows platform

Rust crate for ghost-frame call-stack spoofing, runtime indirect syscalls, and APC injection on Windows x64. Provides SSN resolution, JIT stub…

A Cobalt Strike memory evasion loader for redteamers

UEFI rootkit under development focusing on privilege escalation, C2 integration, and anti-EDR/AV evasion for real-world malware deployment.