-
BOAZ_beta Public
Forked from thomasxm/BOAZ_betaMultilayered AV/EDR Evasion Framework
C++ GNU General Public License v3.0 UpdatedMar 12, 2025 -
PPL-0day Public
Forked from pulpocaminante/PPL-0dayDemoting PPL anti-malware services to less than a guest user
-
GH-Injector-Library Public
Forked from guidedhacking/GuidedHacking-InjectorA feature rich DLL injection library.
-
r77-rootkit Public
Forked from bytecode77/r77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.
-
windows-rootkit Public
Forked from shaygitub/windows-rootkitwindows rootkit
-
Shhhloader Public
Forked from icyguider/ShhhloaderSysWhispers Shellcode Loader (Work in Progress)
-
Nimcrypt2 Public
Forked from icyguider/Nimcrypt2.NET, PE, & Raw Shellcode Packer/Loader Written in Nim
-
xeno-rat Public
Forked from moom825/xeno-ratXeno-RAT is an open-source remote access tool (RAT) developed in C#, providing a comprehensive set of features for remote system management.
-
-
mhydeath Public
Forked from zer0condition/mhydeathAbusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes.
C++ UpdatedAug 22, 2023 -
BlackLotus Public
Forked from ldpreload/BlackLotusBlackLotus UEFI Windows Bootkit
C UpdatedJul 16, 2023 -
-
gryphon Public
Forked from whiterabb17/gryphonTriple OS Malware development framework [ MacOS, Linux & Windows ]
Go UpdatedMay 11, 2023 -
-
Pretend_HideVirtualMemory Public
Forked from A-Normal-User/Pretend_HideVirtualMemory利用物理内存映射,实现虚拟内存的伪隐藏
C++ MIT License UpdatedSep 15, 2022 -
MalwareApiLibrary Public
Forked from MalwareApiLib/MalwareApiLibrarycollection of apis used in malware development
C MIT License UpdatedAug 2, 2022 -
Lunar Public
Forked from Dewera/LunarA lightweight native DLL mapping library that supports mapping directly from memory
C# MIT License UpdatedJul 24, 2022 -
Nidhogg Public
Forked from Idov31/NidhoggNidhogg is an all-in-one simple to use rootkit for red teams.
C++ BSD 2-Clause "Simplified" License UpdatedJul 17, 2022 -
iscsicpl_bypassUAC Public
Forked from hackerhouse-opensource/iscsicpl_bypassUACUAC bypass for x64 Windows 7 - 11
C++ UpdatedJul 14, 2022 -
-
-
Mangle Public
Forked from optiv/MangleMangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs
Go MIT License UpdatedJun 24, 2022 -
FOLIAGE Public
Forked from moonlight-junky/FOLIAGEPublic variation of FOLIAGE ( original developer )
C UpdatedJun 18, 2022 -
Project-Whis Public
Forked from SaturnsVoid/Project-WhisBotnet using a Go and Bootstrap Based C2, Support for Windows, Linux and Android Clients.
JavaScript UpdatedJun 16, 2022 -
bootdoor Public
Forked from RobinFassinaMoschiniForks/bootdoorFormer UEFI Firmware Rootkit Replicating MoonBounce / ESPECTRE
C UpdatedJun 14, 2022 -
TitanLdr Public
Forked from moonlight-junky/TitanLdrPublic variation of Titan Loader
C UpdatedJun 14, 2022 -
Data-Encoder-Crypter-Encoded-Aes-Hidden-Startup Public
Forked from therealelyayo/Data-Encoder-Crypter-Encoded-Aes-Hidden-StartupThe encryption is randomized at every compilation and protected against default bruteforcing.
-
-
directntapi Public
Forked from Fyyre/directntapiDirectNtApi - simple method to make ntapi function call without importing or walking export table. Work under Windows 7, 8 and 10
Assembly MIT License UpdatedApr 27, 2022 -
EagleMonitorRAT Public
Forked from arsium/EagleMonitorRATRemote Access Tool Written In C#