15-stage Windows malware development & analysis course in Rust. Red team builds it, blue team detects it. All 15 binaries achieved 0/76 on VirusTotal.
☆289Mar 27, 2026Updated 3 months ago
Alternatives and similar repositories for goodboy-framework
Users that are interested in goodboy-framework are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Evasive loader for .NET Framework assemblies☆82May 12, 2026Updated 2 months ago
- Polymorphic PE rewriter for Windows x64 , rewrites binaries into semantically identical but byte-different variants☆192Jun 6, 2026Updated last month
- Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.☆393Jun 20, 2026Updated last month
- A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN☆141Jan 26, 2026Updated 5 months ago
- A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.☆59Updated this week
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆46Jun 18, 2026Updated last month
- The dragon in the dark. A red team post exploitation framework for testing security controls during red team assessments.☆507Mar 15, 2026Updated 4 months ago
- Active Directory forensic framework☆16May 18, 2026Updated 2 months ago
- Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)☆107Apr 4, 2026Updated 3 months ago
- Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.☆410Updated this week
- COM Windows Persistence Technique☆89Apr 27, 2026Updated 2 months ago
- A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Slee…☆70Jul 11, 2026Updated last week
- Windows security research toolkit for LPE, persistence, COM hijacking, and attack surface enumeration.☆205Jun 13, 2026Updated last month
- Proof of Concept (PoC) implant for creating custom Cobalt Strike Beacons☆216Feb 11, 2026Updated 5 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- PolyEngine is an evasive PE packer designed for CTF challenges and low-level Windows security education. It focuses on bypassing EDR and …☆148Jun 10, 2026Updated last month
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆311Jul 5, 2026Updated 2 weeks ago
- Lightweight binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy. Designed for red team operations and ephe…☆569Oct 3, 2025Updated 9 months ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago
- Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.☆62May 4, 2026Updated 2 months ago
- Technical Reference to multiple relay techniques☆190May 21, 2026Updated last month
- Phantom is project created to perform loading and executing unmanaged code in memory within an IIS environment running in full‑trust mode…☆107Jun 5, 2026Updated last month
- NØW is a word-based shellcode encoding and obfuscation tool that transforms raw shellcode bytes into natural-looking English prose.☆73Jun 24, 2026Updated 3 weeks ago
- Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods…☆191Apr 27, 2026Updated 2 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Adaptix C2 extender to support Cobalt Strike Malleable C2 profiles☆48Jun 28, 2026Updated 3 weeks ago
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 2 months ago
- .NET CLR-Stomping☆146May 20, 2026Updated 2 months ago
- ☆51Jul 12, 2026Updated last week
- This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found …☆314May 24, 2026Updated last month
- The Azure Execution Tool☆159Feb 6, 2026Updated 5 months ago
- A credential extraction BOF for Veeam Backup and Replication and Veeam One☆79Jul 1, 2026Updated 2 weeks ago
- KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.☆198Jul 8, 2026Updated last week
- Windows绕过EDR实现DumpHash☆247May 10, 2026Updated 2 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Modify machine code in binaries with alternative x64 assembly opcodes for AV evasion☆228Jul 7, 2026Updated last week
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.☆56Mar 30, 2026Updated 3 months ago
- Create local administrators with the SAMR API (lowest-level technique). Implemented in C#, Crystal, Python and Rust☆89Mar 7, 2026Updated 4 months ago
- Polymorphic AV/AMSI bypass toolkit - Donut shellcode runner for offensive .NET/PE tools☆36May 26, 2026Updated last month
- This cheatsheet maps common impacket workflows to their modern alternatives☆301May 30, 2026Updated last month
- DCOM in memory and fileless lateral movement techniques through .Net deserilization☆273Jun 22, 2026Updated 3 weeks ago
- AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64☆542Mar 7, 2026Updated 4 months ago