15-stage Windows malware development & analysis course in Rust. Red team builds it, blue team detects it. All 15 binaries achieved 0/76 on VirusTotal.
☆296Mar 27, 2026Updated 5 months ago
Alternatives and similar repositories for goodboy-framework
Users that are interested in goodboy-framework are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Evasive loader for .NET Framework assemblies☆83May 12, 2026Updated 3 months ago
- Polymorphic PE rewriter for Windows x64 , rewrites binaries into semantically identical but byte-different variants☆201Jun 6, 2026Updated 2 months ago
- Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.☆398Updated this week
- A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN☆181Jan 26, 2026Updated 7 months ago
- A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.☆59Jul 20, 2026Updated last month
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆50Jul 23, 2026Updated last month
- Active Directory forensic framework☆16May 18, 2026Updated 3 months ago
- The dragon in the dark. A red team post exploitation framework for testing security controls during red team assessments.☆510Mar 15, 2026Updated 5 months ago
- Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)☆106Apr 4, 2026Updated 4 months ago
- COM Windows Persistence Technique☆90Apr 27, 2026Updated 4 months ago
- Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.☆420Aug 21, 2026Updated last week
- A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Slee…☆110Jul 26, 2026Updated last month
- Proof of Concept (PoC) implant for creating custom Cobalt Strike Beacons☆217Feb 11, 2026Updated 6 months ago
- PolyEngine is an evasive PE packer designed for CTF challenges and low-level Windows security education. It focuses on bypassing EDR and …☆156Aug 6, 2026Updated 3 weeks ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆316Updated this week
- Lightweight binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy. Designed for red team operations and ephe…☆571Oct 3, 2025Updated 10 months ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 4 months ago
- Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.☆66May 4, 2026Updated 3 months ago
- Technical Reference to multiple relay techniques☆194May 21, 2026Updated 3 months ago
- NØW is a word-based shellcode encoding and obfuscation tool that transforms raw shellcode bytes into natural-looking English prose.☆78Jun 24, 2026Updated 2 months ago
- Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods…☆200Apr 27, 2026Updated 4 months ago
- Phantom is project created to perform loading and executing unmanaged code in memory within an IIS environment running in full‑trust mode…☆107Jun 5, 2026Updated 2 months ago
- Adaptix C2 extender to support Cobalt Strike Malleable C2 profiles☆51Jun 28, 2026Updated 2 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 3 months ago
- .NET CLR-Stomping☆149May 20, 2026Updated 3 months ago
- A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive …☆1,532May 5, 2026Updated 3 months ago
- ☆64Jul 12, 2026Updated last month
- The Azure Execution Tool☆159Feb 6, 2026Updated 6 months ago
- This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found …☆330May 24, 2026Updated 3 months ago
- A credential extraction BOF for Veeam Backup and Replication and Veeam One☆79Jul 1, 2026Updated last month
- KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.☆218Jul 8, 2026Updated last month
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.☆55Mar 30, 2026Updated 5 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Windows绕过EDR实现DumpHash☆252Jul 30, 2026Updated last month
- Modify machine code in binaries with alternative x64 assembly opcodes for AV evasion☆238Jul 7, 2026Updated last month
- Create local administrators with the SAMR API (lowest-level technique). Implemented in C#, Crystal, Python and Rust☆96Aug 17, 2026Updated last week
- Polymorphic AV/AMSI bypass toolkit - Donut shellcode runner for offensive .NET/PE tools☆36May 26, 2026Updated 3 months ago
- This cheatsheet maps common impacket workflows to their modern alternatives☆304May 30, 2026Updated 3 months ago
- DCOM in memory and fileless lateral movement techniques through .Net deserilization☆290Jun 22, 2026Updated 2 months ago
- Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijac…☆158Jul 20, 2026Updated last month