☆73Dec 19, 2024Updated last year
Alternatives and similar repositories for CallStackSpoofer
Users that are interested in CallStackSpoofer are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆37Nov 8, 2024Updated last year
- BOF with Synthetic Stackframe☆257Oct 30, 2025Updated 8 months ago
- ☆23May 19, 2026Updated 2 months ago
- Evasion kit for Cobalt Strike☆479Jun 5, 2026Updated last month
- A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike☆236Apr 11, 2026Updated 3 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- RunPE implementation with multiple evasive techniques (2)☆283Sep 25, 2025Updated 9 months ago
- Lab research on Windows loader internals, PE loading, stack artifacts, and execution tradeoffs.☆237May 4, 2026Updated 2 months ago
- Using call gadgets to break the call stack signature used by Elastic on proxying a module load. Provided as a Crystal Palace shared libra…☆87Nov 6, 2025Updated 8 months ago
- Implementing Ghostly-Hollowing using tampered syscalls for remote PE injection☆74Dec 26, 2025Updated 6 months ago
- A PoC UDRL for Cobalt Strike built with Crystal Palace that combines Raphael Mudge's page streaming technique with a modular call gate (D…☆134Jan 21, 2026Updated 6 months ago
- A collection of DPAPI hunting and parsing BOFs☆38Mar 3, 2026Updated 4 months ago
- Crystal Palace library for proxying Nt API calls via the Threadpool☆105Oct 18, 2025Updated 9 months ago
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆311Jul 5, 2026Updated 2 weeks ago
- Cobaltstrike Reflective Loader with Synthetic Stackframe☆193Jan 17, 2026Updated 6 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- A BOF that's a BOF Loader and more☆209Apr 6, 2026Updated 3 months ago
- A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.☆139Jan 28, 2026Updated 5 months ago
- Language extension for Crystal Palace Specification files☆15Jun 6, 2026Updated last month
- Clean Indirect Syscalls with Hook Evasion & Return Address Spoofing.☆98Apr 30, 2026Updated 2 months ago
- BingusLdr is a DLL loader built with Crystal Palace that uses a CET compatible stack spoofing technique.☆89Updated this week
- ☆85Feb 12, 2026Updated 5 months ago
- Shellcode injection using the Windows Debugging API☆183Jan 4, 2026Updated 6 months ago
- various methods of making API calls☆19Feb 1, 2025Updated last year
- Next-Generation BOF Template | BOF Linter | Obj Rewriter☆58Dec 4, 2025Updated 7 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Cross-platform CPU-based virtual machine detection framework for modern offensive security.☆48Feb 28, 2026Updated 4 months ago
- Dll injection through code page id modification in registry. Based on jonas lykk research☆16Jun 18, 2022Updated 4 years ago
- Boilerplate to develop raw and truly Position Independent Code (PIC).☆117Jan 20, 2025Updated last year
- ☆70Apr 20, 2026Updated 3 months ago
- Cobalt Strike BOF for beacon/shellcode injection using fork & run technique with Draugr synthetic stack frames☆156Nov 23, 2025Updated 7 months ago
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.☆56Mar 30, 2026Updated 3 months ago
- dcsync bof☆54Feb 13, 2026Updated 5 months ago
- Find jmp gadgets for call stack spoofing.☆85Oct 1, 2025Updated 9 months ago
- A cmake template for crystal palace☆43Dec 20, 2025Updated 7 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Async BOF to automatically extract or renew Kerberos TGTs on a target system.☆134Updated this week
- ☆52Feb 12, 2026Updated 5 months ago
- PIC shellcode (C/C++) development toolkit designed for malware developers.☆130Dec 23, 2025Updated 6 months ago
- Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR …☆311Jul 31, 2024Updated last year
- ☆110Aug 21, 2024Updated last year
- Beacon Object File (BOF) to obtain Entra tokens via authcode flow.☆139Jan 17, 2026Updated 6 months ago
- Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.☆410Updated this week