
acheron
indirect syscalls for AV/EDR evasion in Go assembly

indirect syscalls for AV/EDR evasion in Go assembly

Combines AppDomain Manager injection with shellcode embedding in signed binaries to evade EDR/AV detection for red team payloads.

Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

NTP-based backdoor for hardened networks, delivering and executing arbitrary shellcode via spoofed NTP traffic with optional persistence as a Windows…


C# tool that generates malicious VBA macros with shellcode injection, VBA purging, and sandbox detection for red team operations.

Assist reverse tcp shells in post-exploration tasks

Adversary Emulation Framework

PoCs and tools for investigation of Windows process execution techniques

Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with…

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

A Golang implant that uses Slack as a command and control server

Hershell is a simple TCP reverse shell written in Go.

A C2 post-exploitation framework

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

Native syscall shellcode injector using HellsGate/HalosGate/TartarusGate for undetectable execution, with external shellcode loading and EDR evasion…

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…