
ScareCrow
ScareCrow - Payload creation framework designed around EDR bypass.

Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing…

Emulate and Dissect MSF and *other* attacks

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

Polymorphic encryptor that transforms shellcode, PE, and COFF files into obfuscated, position-independent payloads with RC4 and random block cipher…

evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)

Nim-based assembly packer and shellcode loader for opsec & profit

Obfusk8: lightweight Obfuscation library based on C++17 / Header Only for windows binaries

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners…

Cooolis-ms是一个包含了Metasploit Payload Loader、Cobalt Strike External C2 Loader、Reflective DLL injection的代码执行工具,它的定位在于能够在静态查杀上规避一些我们将要执行且含有特征的代码,帮助红队人员更方便快…

Automated ROP chain builder that extracts and analyzes gadgets from binaries using semantic queries, supporting X86/X64 architectures with a Python…

RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.

Public repository for improvements to the EXTRABACON exploit

template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.

Crystal Palace Evasion kit for Sliver

open source port/reimplementation of the Cobalt Strike BOF Loader as is

Cobalt Strike UDRL that performs advanced module stomping using VEH to intercept calls, unmap modules during sleep, and remap fresh modules to evade…

Rust-based User-Defined Reflective Loader for Cobalt Strike payloads. Avoids RWX memory pages for OPSEC safety. Includes an extractor tool for loader…