A fileless C2 framework written in pure x64 Linux Assembly with zero libc dependencies. Features dynamic protocol pivoting between raw ICMP sockets and DNS (UDP/53) via in-memory VTable manipulation. 100% direct syscalls, no disk writes, and strict mathematical packet authentication.
☆86Jun 5, 2026Updated last month
Alternatives and similar repositories for ICMP-Ghost-A-Fileless-x64-Assembly-C2-Agent
Users that are interested in ICMP-Ghost-A-Fileless-x64-Assembly-C2-Agent are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Phantom-Evasion-Loader is a standalone, pure x64 Assembly injection engine engineered to minimize the detection surface of modern EDR/XDR…☆109Jul 20, 2026Updated 2 weeks ago
- Modify machine code in binaries with alternative x64 assembly opcodes for AV evasion☆231Jul 7, 2026Updated 3 weeks ago
- Stack spoofing Detection for CET processes by comparing shadow and user stacks.☆39May 22, 2026Updated 2 months ago
- Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advance…☆114Jun 30, 2026Updated last month
- A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.☆58Jul 20, 2026Updated 2 weeks ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Beacon Object Files (BOFs) for Cobalt Strike and Havoc C2. Implementations of Active Directory attacks and post-exploitation techniques.☆118Jan 26, 2026Updated 6 months ago
- PolyEngine is an evasive PE packer designed for CTF challenges and low-level Windows security education. It focuses on bypassing EDR and …☆152Updated this week
- A compiled language for Windows position-independent x86-64 shellcode and Beacon Object Files.☆176Jun 28, 2026Updated last month
- Busybox-style Beacon Object Files for *nix post-exploitation. Reimplements common Unix utilities as BOFs for use in stripped environments…☆83Jul 5, 2026Updated 3 weeks ago
- In-depth reverse engineering of a suspected LockBit affiliate dropper, documenting shellcode loading, import polymorphism, and payload de…☆15Jan 24, 2026Updated 6 months ago
- Modern PIC implant for Windows (64 & 32 bit)☆105Jul 23, 2025Updated last year
- Polymorphic PE rewriter for Windows x64 , rewrites binaries into semantically identical but byte-different variants☆200Jun 6, 2026Updated last month
- BOF POC of the DSCourier project / invoking WinGet via COM☆90Apr 23, 2026Updated 3 months ago
- Open Source Implementation of Cobalt Strike's Malleable C2☆106Jun 27, 2026Updated last month
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Reimplementing Havoc Pro Runtime Channel Switching and Cobalt Strike UDC2 features.☆49Jul 25, 2026Updated last week
- Fritter is a heavily modified fork of TheWover and Odzhan's Donut shellcode generator.☆246Jun 11, 2026Updated last month
- goLoL is a Windows host scanner with dual support for LOLBAS binaries and LOLDrivers. It lists LOLBAS techniques runnable at your current…☆66Jun 28, 2026Updated last month
- Havoc C2 BOF port of the KslD.sys BYOVD technique. Credential extraction from lsass via physical memory — no OpenProcess, no auditable AP…☆145Apr 22, 2026Updated 3 months ago
- Cobalt Strike BOF☆59Dec 10, 2025Updated 7 months ago
- ☆247Mar 13, 2026Updated 4 months ago
- WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.☆105Jun 24, 2026Updated last month
- Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.☆414Updated this week
- ☆58Jul 12, 2026Updated 3 weeks ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Toolset to manipulate RPC clients by finding delayed services and masquerading as them☆114Apr 28, 2026Updated 3 months ago
- COM Windows Persistence Technique☆90Apr 27, 2026Updated 3 months ago
- Lnk crafting and research tools☆185Mar 4, 2026Updated 4 months ago
- SOCKS5 proxy tool that uses Azure Storage services as a means of communication.☆361Mar 21, 2026Updated 4 months ago
- Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)☆107Apr 4, 2026Updated 3 months ago
- ASPX Web Shell with COFF Loader☆134Mar 10, 2026Updated 4 months ago
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆277Apr 16, 2026Updated 3 months ago
- first public in-process reflective PE loader for .NET NativeAOT binaries. maps a NativeAOT executable into the current process and execut…☆28Mar 28, 2026Updated 4 months ago
- .NET CLR-Stomping☆147May 20, 2026Updated 2 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- An example UDC2 implementation for CrystalC2.☆18Jun 19, 2026Updated last month
- A Telegram bot interface for the Adaptix C2 Teamserver. Manage agents, execute commands, handle credentials, view tasks, and download fil…☆21Mar 9, 2026Updated 4 months ago
- AD ACL Abuser for Havoc C2☆25Mar 30, 2026Updated 4 months ago
- Proof of Concept (PoC) implant for creating custom Cobalt Strike Beacons☆218Feb 11, 2026Updated 5 months ago
- Rust 重构的 sRDI☆18Sep 9, 2024Updated last year
- A self-hosted, real-time collaborative workspace for offensive security assessments.☆42Feb 20, 2026Updated 5 months ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago