(WIP) A Recursive UDRL leveraging smelly_vx's Feverdream trick.
☆19Sep 3, 2025Updated 10 months ago
Alternatives and similar repositories for SweetDream
Users that are interested in SweetDream are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Stack spoofing Detection for CET processes by comparing shadow and user stacks.☆39May 22, 2026Updated last month
- Busybox-style Beacon Object Files for *nix post-exploitation. Reimplements common Unix utilities as BOFs for use in stripped environments…☆82Jul 5, 2026Updated 2 weeks ago
- Power Automate C2 (PAC2) : Stealth living-off-the-cloud C2 framework.☆39Apr 16, 2024Updated 2 years ago
- Orchestrate detonating redteam artifacts in VMs with different EDRs to see their detection surface.☆63Jun 24, 2026Updated 3 weeks ago
- Async BOF to monitor and detect clipboard changes on a target system and return the clipboard contents.☆22May 5, 2026Updated 2 months ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- A modern alternative Web-UI for the Mythic Command and Control Server☆79Jul 3, 2026Updated 2 weeks ago
- Reimplementing Havoc Pro Runtime Channel Switching and Cobalt Strike UDC2 features.☆47Jun 23, 2026Updated 3 weeks ago
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.☆56Mar 30, 2026Updated 3 months ago
- Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.☆23Nov 11, 2025Updated 8 months ago
- Async BOF that notifies the operator when a user connects to a local or remote target system.☆34Jun 17, 2026Updated last month
- The standard Go net.Conn interface using Azure Storage services as the transport layer.☆32Mar 19, 2026Updated 4 months ago
- A x64 Position Independent Proxy Enumerator Shellcode (PIPES)☆27Nov 14, 2025Updated 8 months ago
- Beacon Object File (BOF) for Windows Session Hijacking via IHxHelpPaneServer COM☆71Dec 25, 2025Updated 6 months ago
- Cobaltstrike UDRL with memory evasion☆15May 16, 2024Updated 2 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Havoc C2 BOF — WFP kernel-space SYSTEM escalation + command execution with indirect syscalls, patchless AMSI/ETW bypass, and return addre…☆79Mar 22, 2026Updated 3 months ago
- Linux Process Injection via Seccomp Notifier☆95Dec 9, 2025Updated 7 months ago
- Rusty DoublePulsar - Cobalt Strike User-Defined Reflective Loader (UDRL) in Rust (Codename: DoublePulsar)☆115May 14, 2026Updated 2 months ago
- ☆85Feb 12, 2026Updated 5 months ago
- Havoc C2 BOF port of the KslD.sys BYOVD technique. Credential extraction from lsass via physical memory — no OpenProcess, no auditable AP…☆143Apr 22, 2026Updated 2 months ago
- Minimalistic HTTP(S) client for the NT kernel☆61Dec 1, 2025Updated 7 months ago
- BOF POC of the DSCourier project / invoking WinGet via COM☆90Apr 23, 2026Updated 2 months ago
- A userland rootkit☆18May 3, 2026Updated 2 months ago
- psexec-like remote execution using the paexec wire protocol that supports paexec and remoteexecm2 from manageengine adselfservice plus☆43Mar 24, 2026Updated 3 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- A tool that helps change the recovery configuration of a Windows service to make lateral movement more stealthy☆43Feb 8, 2026Updated 5 months ago
- A Cobalt Strike BOF implementation of the SilentHarvest registry dumping technique☆182Apr 14, 2026Updated 3 months ago
- arm64 linux position-independent shellcode framework☆32Dec 12, 2025Updated 7 months ago
- A protracted people's rootkit.☆19May 1, 2026Updated 2 months ago
- Rusty Armory - Beacon Object Files (BOFs) in Rust (Codename: Armory)☆71Apr 3, 2026Updated 3 months ago
- Parser for Windows Defender Detection history files.☆19Nov 26, 2025Updated 7 months ago
- A simple POC to show how to chain multiple callbacks via tail calls to artificially construct a call stack☆109May 25, 2026Updated last month
- An example UDC2 implementation for CrystalC2.☆18Jun 19, 2026Updated last month
- Phantom-Evasion-Loader is a standalone, pure x64 Assembly injection engine engineered to minimize the detection surface of modern EDR/XDR…☆109Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Dll injection through code page id modification in registry. Based on jonas lykk research☆16Jun 18, 2022Updated 4 years ago
- A PoC UDRL for Cobalt Strike built with Crystal Palace that combines Raphael Mudge's page streaming technique with a modular call gate (D…☆134Jan 21, 2026Updated 5 months ago
- Progressing on my malware development journey.☆17Aug 20, 2024Updated last year
- ☆138Nov 16, 2024Updated last year
- Havoc Professional backend plugin to allow ingesting of events and logs to Ghostwriter☆16Feb 25, 2026Updated 4 months ago
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆26May 10, 2026Updated 2 months ago
- Service Extender for notifying about AdaptixC2 events in Telegram, Slack, Rocket.Char, Discord, and any web platforms, such as ntfy.sh.☆19Mar 4, 2026Updated 4 months ago