
Empire
Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.

IDPS & SandBox & AntiVirus STEALTH KILLER. MorphAES is the world's first polymorphic shellcode engine, with metamorphic properties and capability to…

Kage is Graphical User Interface for Metasploit Meterpreter and Session Handler

EGESPLOIT is a golang library for malware development

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Adversary Emulation Framework

Polymorphic binary encoder for offensive security payloads. Encodes shellcode with LFSR-based feedback loop, garbage instruction injection, and…

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

PoCs and tools for investigation of Windows process execution techniques

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Python AV Evasion Tools

Go shellcode loader that combines multiple evasion techniques

Deploy payloads to *Nix systems en masse

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.