(WIP) A Recursive UDRL leveraging smelly_vx's Feverdream trick.
☆19Sep 3, 2025Updated last year
Alternatives and similar repositories for SweetDream
Users that are interested in SweetDream are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Stack spoofing Detection for CET processes by comparing shadow and user stacks.☆38May 22, 2026Updated 3 months ago
- Busybox-style Beacon Object Files for *nix post-exploitation. Reimplements common Unix utilities as BOFs for use in stripped environments…☆83Aug 22, 2026Updated 3 weeks ago
- Orchestrate detonating redteam artifacts in VMs with different EDRs to see their detection surface.☆89Sep 7, 2026Updated last week
- Power Automate C2 (PAC2) : Stealth living-off-the-cloud C2 framework.☆39Apr 16, 2024Updated 2 years ago
- A modern alternative Web-UI for the Mythic Command and Control Server☆82Jul 3, 2026Updated 2 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Async BOF to monitor and detect clipboard changes on a target system and return the clipboard contents.☆22Jul 23, 2026Updated last month
- Reimplementing Havoc Pro Runtime Channel Switching and Cobalt Strike UDC2 features.☆54Updated this week
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.☆55Mar 30, 2026Updated 5 months ago
- Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.☆23Nov 11, 2025Updated 10 months ago
- Async BOF that notifies the operator when a user connects to a local or remote target system.☆34Jul 30, 2026Updated last month
- The standard Go net.Conn interface using Azure Storage services as the transport layer.☆32Aug 15, 2026Updated last month
- A x64 Position Independent Proxy Enumerator Shellcode (PIPES)☆26Nov 14, 2025Updated 10 months ago
- Beacon Object File (BOF) for Windows Session Hijacking via IHxHelpPaneServer COM☆71Dec 25, 2025Updated 8 months ago
- Linux Process Injection via Seccomp Notifier☆95Dec 9, 2025Updated 9 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A runtime for developing large-scale and complex PIC module.☆21Updated this week
- Rusty DoublePulsar - Cobalt Strike User-Defined Reflective Loader (UDRL) in Rust (Codename: DoublePulsar)☆117May 14, 2026Updated 4 months ago
- ☆88Feb 12, 2026Updated 7 months ago
- Havoc C2 BOF port of the KslD.sys BYOVD technique. Credential extraction from lsass via physical memory — no OpenProcess, no auditable AP…☆146Apr 22, 2026Updated 4 months ago
- Minimalistic HTTP(S) client for the NT kernel☆60Dec 1, 2025Updated 9 months ago
- BOF POC of the DSCourier project / invoking WinGet via COM☆90Apr 23, 2026Updated 4 months ago
- A userland rootkit☆18May 3, 2026Updated 4 months ago
- psexec-like remote execution using the paexec wire protocol that supports paexec and remoteexecm2 from manageengine adselfservice plus☆44Mar 24, 2026Updated 5 months ago
- A tool that helps change the recovery configuration of a Windows service to make lateral movement more stealthy☆44Feb 8, 2026Updated 7 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A Cobalt Strike BOF implementation of the SilentHarvest registry dumping technique☆181Apr 14, 2026Updated 5 months ago
- Rust Armory - Cobalt Strike Beacon Object Files (BOFs) in Rust for situational awareness, remote operations, and post-exploitation tradec…☆71Updated this week
- A protracted people's rootkit.☆19May 1, 2026Updated 4 months ago
- arm64 linux position-independent shellcode framework☆31Dec 12, 2025Updated 9 months ago
- Cobaltstrike UDRL with memory evasion☆14May 16, 2024Updated 2 years ago
- Parser for Windows Defender Detection history files.☆20Nov 26, 2025Updated 9 months ago
- A simple POC to show how to chain multiple callbacks via tail calls to artificially construct a call stack☆111May 25, 2026Updated 3 months ago
- An example UDC2 implementation for CrystalC2.☆18Jun 19, 2026Updated 2 months ago
- Phantom-Evasion-Loader is a standalone, pure x64 Assembly injection engine engineered to minimize the detection surface of modern EDR/XDR…☆111Aug 8, 2026Updated last month
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Dll injection through code page id modification in registry. Based on jonas lykk research☆16Jun 18, 2022Updated 4 years ago
- A PoC UDRL for Cobalt Strike built with Crystal Palace that combines Raphael Mudge's page streaming technique with a modular call gate (D…☆139Jan 21, 2026Updated 7 months ago
- Progressing on my malware development journey.☆17Aug 20, 2024Updated 2 years ago
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆26May 10, 2026Updated 4 months ago
- ☆141Nov 16, 2024Updated last year
- Service Extender for notifying about AdaptixC2 events in Telegram, Slack, Rocket.Char, Discord, and any web platforms, such as ntfy.sh.☆22Mar 4, 2026Updated 6 months ago
- Havoc Professional backend plugin to allow ingesting of events and logs to Ghostwriter☆16Feb 25, 2026Updated 6 months ago