
frostbyte
Combines AppDomain Manager injection with shellcode embedding in signed binaries to evade EDR/AV detection for red team payloads.

Combines AppDomain Manager injection with shellcode embedding in signed binaries to evade EDR/AV detection for red team payloads.

C# tool that generates malicious VBA macros with shellcode injection, VBA purging, and sandbox detection for red team operations.

Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

NTP-based backdoor for hardened networks, delivering and executing arbitrary shellcode via spoofed NTP traffic with optional persistence as a Windows…


indirect syscalls for AV/EDR evasion in Go assembly

Assist reverse tcp shells in post-exploration tasks

Adversary Emulation Framework

Pack shellcode and PE executables into evasive payloads with anti-debug, unhooking, syscall, and memory fluctuation techniques for red-team…

Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with…

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

PoCs and tools for investigation of Windows process execution techniques

A Golang implant that uses Slack as a command and control server

Hershell is a simple TCP reverse shell written in Go.

A C2 post-exploitation framework

Fileless lateral movement tool using WMI Event Subscriptions to execute .NET assemblies in memory, with shellcode injection via named pipes for…

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

DNS-Persist is a post-exploitation agent which uses DNS for command and control.