Malformed ZIP archive that evades antivirus detection by declaring Method=0 (stored) while containing DEFLATE-compressed payload.
☆196Mar 19, 2026Updated 6 months ago
Alternatives and similar repositories for zombie-zip
Users that are interested in zombie-zip are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Netlogon and CLDAP vulnerability research with a proof of concept.☆231Jun 2, 2026Updated 4 months ago
- Lnk crafting and research tools☆185Mar 4, 2026Updated 6 months ago
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆281Apr 16, 2026Updated 5 months ago
- ☆70Jul 12, 2026Updated 2 months ago
- Cobaltstrike UDRL with memory evasion☆14May 16, 2024Updated 2 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- COM Windows Persistence Technique☆89Apr 27, 2026Updated 5 months ago
- PPLReaper is a Windows UNSIGNED kernel driver + userland companion tool designed to inspect and manipulate Protected Process Light (PPL) …☆25Mar 4, 2026Updated 6 months ago
- Async BOF to automatically extract or renew Kerberos TGTs on a target system.☆137Jul 23, 2026Updated 2 months ago
- Cobalt Strike BOF to obtain location data☆29Jul 4, 2026Updated 2 months ago
- A PoC UDRL for Cobalt Strike built with Crystal Palace that combines Raphael Mudge's page streaming technique with a modular call gate (D…☆140Jan 21, 2026Updated 8 months ago
- A BOF designed to inspect processes memory and addresses☆41Apr 19, 2026Updated 5 months ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆118Dec 21, 2025Updated 9 months ago
- EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies☆49Jun 8, 2026Updated 3 months ago
- SafeHarbor revamped with Direct Syscalls using InlineWhispers3☆14Feb 16, 2026Updated 7 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Busybox-style Beacon Object Files for *nix post-exploitation. Reimplements common Unix utilities as BOFs for use in stripped environments…☆83Aug 22, 2026Updated last month
- Project for generating and identifying deceptive LNK files.☆389Aug 10, 2026Updated last month
- Havoc BOF implementation of BYOVD attack to terminate PPL-protected EDR processes using a signed Microsoft kernel driver.☆39Apr 6, 2026Updated 5 months ago
- An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard histor…☆117Apr 16, 2026Updated 5 months ago
- Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable…☆35Mar 28, 2026Updated 6 months ago
- PoC for popping a system shell against the LnvMSRIO.sys driver☆126Oct 6, 2025Updated 11 months ago
- ghost-bits-encoder 是一个面向 Woodpecker 的辅助插件,围绕 Ghost Bits / Unicode 高位包装思路,提供通用编解码、JSON 相关编码、URL 相关编码以及若干专项辅助能力。☆55May 15, 2026Updated 4 months ago
- Using Chromium-based browsers as a proxy for C2 traffic.☆155Dec 6, 2025Updated 9 months ago
- A BOF that's a BOF Loader and more☆212Apr 6, 2026Updated 5 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- RPC计划任务维权-过核晶☆14May 19, 2026Updated 4 months ago
- A tool to automate MS Direct Send emails☆21Mar 16, 2026Updated 6 months ago
- test☆107Apr 25, 2026Updated 5 months ago
- DSCourier is a proof-of-concept that uses the WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries.☆210Jun 25, 2026Updated 3 months ago
- Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass☆146Jan 29, 2026Updated 8 months ago
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆51Jul 23, 2026Updated 2 months ago
- Self-cleaning in-memory PICO loader for Crystal Palace. Automatically erases traces and operates entirely in memory for stealthy payload …☆59Nov 2, 2025Updated 11 months ago
- Extract Windows credentials directly from VM memory snapshots and virtual disks☆1,628Updated this week
- abusing windows toast notifications for fun and user manipulation☆106Jul 11, 2026Updated 2 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- TongWebEJB漏洞利用工具☆32Apr 24, 2026Updated 5 months ago
- BOF POC of the DSCourier project / invoking WinGet via COM☆90Apr 23, 2026Updated 5 months ago
- Useful Cobalt Strike Beacon Object Files (BOFs) used during red teaming and penetration testing engagements.☆163May 30, 2022Updated 4 years ago
- A stealthier approach to WMI-based command execution using Impacket without touching the disk.☆86Mar 15, 2026Updated 6 months ago
- A Windows x64 offensive research framework that constructs fully synthetic call stacks☆73Jul 14, 2026Updated 2 months ago
- BOF for Havoc that copies locked Windows files (SAM, SYSTEM, NTDS.dit) via raw MFT parsing — no VSS, no Registry APIs, no PowerShell☆135Apr 6, 2026Updated 5 months ago
- Windows Error Reporting ALPC Elevation of Privilege (CVE-2026-20817) - Proof-of-Concept exploit demonstrating local privilege escalation …☆129Feb 19, 2026Updated 7 months ago