Immersive-Labs-Sec / HavocC2-ForensicsView external linksLinks
A set of tools and resources for analysis of Havoc C2
☆26Feb 27, 2024Updated last year
Alternatives and similar repositories for HavocC2-Forensics
Users that are interested in HavocC2-Forensics are comparing it to the libraries listed below
Sorting:
- Automated script for obfuscating, rebranding and renaming the Havoc C2 Framework to evade AV/EDR and C2 hunters.☆46Aug 13, 2025Updated 6 months ago
- A python tool to parse and describe the SDDL string.☆17Jan 5, 2026Updated last month
- process hollowing variant using NtCreateSection + NtMapViewOfSection + ResumeThread☆31Jan 9, 2022Updated 4 years ago
- Templates for developing your own listeners and agents for AdaptixC2.☆44Feb 3, 2026Updated last week
- A ring0 Loadable Kernel Module (Linux) for latest kernels 6.x☆103Dec 16, 2025Updated last month
- Using Just In Time (JIT) instruction decryption, this shellcode loader ensures that only the currently executing instruction is visible i…☆63Apr 2, 2025Updated 10 months ago
- Find kernel32 base and API addresses. Simple C++ implementation☆24Apr 7, 2022Updated 3 years ago
- Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and…☆152Feb 2, 2026Updated last week
- Run payload like a Lazarus Group (UuidFromStringA). C++ implementation☆20Jul 24, 2022Updated 3 years ago
- Generate Proxy DLLs in Rust☆47Sep 2, 2025Updated 5 months ago
- powershell script i wrote that can suspend an arbitrary process (with limits)☆22Mar 26, 2023Updated 2 years ago
- NSecSoftBYOVD POC☆55Updated this week
- Abusing SSRF to deliver an authenticated command injection payload☆30Sep 1, 2025Updated 5 months ago
- Another version of .NET loader provides capabilities of bypassing ETW and AMSI, utilizing VEH for syscalls and loading .NET assemblies☆50Jul 6, 2025Updated 7 months ago
- .NET assembly loader with patching AMSI and ETW bypass☆31Apr 16, 2025Updated 9 months ago
- GetModuleHandle (via PEB) and GetProcAddress (via EAT) like☆32Feb 7, 2022Updated 4 years ago
- ☆48Jun 6, 2025Updated 8 months ago
- Stuxnet extracted binaries by reversing & Stuxnet Rootkit Analysis☆85Sep 14, 2024Updated last year
- Malware AV evasion via disable Windows Defender (Registry). C++☆35Jun 5, 2022Updated 3 years ago
- ☆41Feb 20, 2025Updated 11 months ago
- A program for obfuscating C strings☆36Feb 26, 2023Updated 2 years ago
- Static binary analysis with Detect It Easy — 100% in your browser, no uploads.☆53Updated this week
- OsintifyX: Powerful Open-source OSINT tool for extracting valuable information from Instagram profiles. OSINT: Instagram Forensics Tool☆11Feb 19, 2024Updated last year
- converts sRDI compatible dlls to shellcode☆35Jan 20, 2025Updated last year
- A Beacon Object File (BOF) for Havoc/CS to Bypass PPL and Dump Lsass☆165Sep 22, 2025Updated 4 months ago
- ☆41Sep 9, 2023Updated 2 years ago
- ☆35Dec 6, 2023Updated 2 years ago
- Laravel RCE Exploitation Toolkit☆55Nov 8, 2025Updated 3 months ago
- Beacon Object Files (BOFs) for Cobalt Strike and Havoc C2. Implementations of Active Directory attacks and post-exploitation techniques.☆99Jan 26, 2026Updated 2 weeks ago
- Simple HTTP async comms using standard GET/POST requests☆46Feb 5, 2026Updated last week
- Random BOFs for LDAP tradecraft☆72Sep 9, 2025Updated 5 months ago
- 一个用于暴力破解猫变换(Arnold's Cat Map)加密图像的命令行工具。☆26Dec 21, 2025Updated last month
- Challenge 1 of The Auror Project - Setup AD Lab automatically☆12Apr 26, 2022Updated 3 years ago
- Bypassing Amsi using LdrLoadDll☆47Jan 8, 2025Updated last year
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆88Jan 2, 2026Updated last month
- WinDbg plugin to trace module transitions from a debugged driver.☆40Dec 22, 2025Updated last month
- Telegram base free Rat☆11Apr 26, 2025Updated 9 months ago
- This repository contains a collection of scripts I use regularly for offensive security-related tasks.☆15Jan 17, 2026Updated 3 weeks ago
- A collection of FreeBSD rootkit kernel modules and utilities☆13Jun 25, 2025Updated 7 months ago