
SysWhispers
AV/EDR evasion via direct system calls.

AV/EDR evasion via direct system calls.

SSH-based reverse shell management tool with native SCP/SFTP support, multiple transport protocols, Windows DLL generation, and fileless execution…

Polymorphic binary encoder for offensive security payloads. Encodes shellcode with LFSR-based feedback loop, garbage instruction injection, and…

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

Reflective PE packer.

EXOCET - AV-evading, undetectable, payload delivery tool

A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.

Multiplatform reverse shell generator

A Golang implant that uses Slack as a command and control server

Create fake certs for binaries using windows binaries and the power of bat files


Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

A POC of a new “threadless” process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote…

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

A QoL tool to obfuscate shellcode. In the future will be able to chain encoding/encryption/compression methods.

C# tool that generates malicious VBA macros with shellcode injection, VBA purging, and sandbox detection for red team operations.


KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…