SHAREM is a shellcode analysis framework, capable of emulating more than 45,000 WinAPIs and virutally all Windows syscalls. It also contains its own custom disassembler, with many innovative features, such as being able to show the deobfuscated disassembly of an encoded shellcode, or integrating emulation data to enhance the disassembly.
☆492Mar 22, 2026Updated 4 months ago
Alternatives and similar repositories for sharem
Users that are interested in sharem are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ShellWasp is a tool to help build shellcode that utilizes Windows syscalls, while overcoming the portability problem associated with Wind…☆177Aug 5, 2026Updated last week
- Dont Call Me Back - Dynamic kernel callback resolver. Scan kernel callbacks in your system in a matter of seconds!☆254Jul 9, 2024Updated 2 years ago
- Helper script for Windows kernel debugging with IDA Pro on native Bochs debugger (including PDB symbols)☆62Aug 11, 2023Updated 3 years ago
- A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.ht…☆678Dec 23, 2022Updated 3 years ago
- Cobalt Strike UDRL for memory scanner evasion.☆1,031Jun 4, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆840Mar 16, 2024Updated 2 years ago
- PoC Implementation of a fully dynamic call stack spoofer☆986Jul 20, 2024Updated 2 years ago
- Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll☆513Feb 3, 2022Updated 4 years ago
- A modern 32/64-bit position independent implant template☆1,359Jun 1, 2026Updated 2 months ago
- A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementin…☆538Aug 1, 2022Updated 4 years ago
- Windows kernel and user mode emulation.☆2,027Updated this week
- Converts PE into a shellcode☆2,789Aug 30, 2025Updated 11 months ago
- Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel space☆135Jan 2, 2023Updated 3 years ago
- Performing Indirect Clean Syscalls☆623May 2, 2026Updated 3 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A tool to kill antimalware protected processes☆1,526Jun 19, 2021Updated 5 years ago
- AV/EDR evasion via direct system calls.☆1,825Sep 3, 2022Updated 3 years ago
- kill anti-malware protected processes ( BYOVD )☆986Jul 21, 2023Updated 3 years ago
- Shoggoth: Asmjit Based Polymorphic Encryptor☆806Apr 4, 2026Updated 4 months ago
- PoCs and tools for investigation of Windows process execution techniques☆958Feb 2, 2026Updated 6 months ago
- Dynamic unpacker based on PE-sieve☆833Apr 14, 2026Updated 4 months ago
- A memory-based evasion technique which makes shellcode invisible from process start to end.☆1,201Oct 16, 2023Updated 2 years ago
- An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting…☆1,126Jun 17, 2022Updated 4 years ago
- A PoC of the ContainYourself research presented in DEFCON 31, which abuses the Windows containers framework to bypass EDRs.☆319Aug 31, 2023Updated 2 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.☆736Jul 19, 2023Updated 3 years ago
- SysWhispers on Steroids - AV/EDR evasion via direct system calls.☆1,651Jul 31, 2024Updated 2 years ago
- A Pin Tool for tracing API calls etc☆1,686Jun 2, 2026Updated 2 months ago
- Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes☆1,061Jun 20, 2023Updated 3 years ago
- x86 malware emulator☆313Updated this week
- RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, …☆499Jan 25, 2022Updated 4 years ago
- laZzzy is a shellcode loader, developed using different open-source libraries, that demonstrates different execution techniques.☆505Jan 10, 2023Updated 3 years ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆127Jul 12, 2024Updated 2 years ago
- Enumerate various traits from Windows processes as an aid to threat hunting☆200Jan 13, 2022Updated 4 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- A small program written in C that is designed to load 32/64-bit shellcode and allow for execution or debugging. Can also output PE files …☆178Jul 20, 2024Updated 2 years ago
- An example of how a driver can register a handle creation callback.☆16Jun 12, 2023Updated 3 years ago
- Hiding shellcode in plain sight within a large memory region. Inspired by technique used by Raspberry Robin's Roshtyak☆210Nov 12, 2025Updated 9 months ago
- Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.☆2,458Jun 26, 2026Updated last month
- A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.☆411Jan 11, 2026Updated 7 months ago
- x64 binary obfuscator☆1,989Jul 14, 2023Updated 3 years ago
- Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.☆327Apr 12, 2024Updated 2 years ago