ShadowPhish is an advanced APT awareness toolkit designed to simulate real-world phishing, malware delivery, deepfakes, smishing/vishing, and command & control attacks through an intuitive graphical interface. Perfect for cybersecurity training, red team education, and security awareness programs.
☆245Apr 18, 2025Updated last year
Alternatives and similar repositories for ShadowPhish
Users that are interested in ShadowPhish are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- General Purpose OpSec Server☆115Mar 13, 2026Updated 6 months ago
- Enumerate Domain Users Without Authentication☆312Apr 22, 2025Updated last year
- Evasion kit for Cobalt Strike☆508Jun 5, 2026Updated 4 months ago
- Dynamic shellcode loader with sophisticated evasion capabilities☆344Oct 1, 2025Updated last year
- Huffman Coding in Shellcode Obfuscation & Dynamic Indirect Syscalls Loader.☆307Apr 6, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A Mythic agent for Windows written in C☆187Aug 22, 2026Updated last month
- smugglo - an easy to use script for wrapping files into self-dropping HTML payloads to bypass content filters☆133Mar 25, 2025Updated last year
- A tool which bypasses AMSI (AntiMalware Scan Interface) and PowerShell CLM (Constrained Language Mode) and gives you a FullLanguage Power…☆819Mar 28, 2025Updated last year
- Weaponizing DCOM for NTLM Authentication Coercions☆273Jul 1, 2025Updated last year
- ☆47Apr 9, 2025Updated last year
- A user-mode code and its rootkit that will Kill EDR Processes permanently by leveraging the power of Process Creation Blocking Kernel Cal…☆265Jun 10, 2025Updated last year
- Permanently disable EDRs as local admin☆132Dec 19, 2025Updated 9 months ago
- Python3 utility for creating zip files that smuggle additional data for later extraction☆275May 15, 2025Updated last year
- LSASS memory dumper using only NTAPIs, creating a minimal minidump. It can be compiled as shellcode (PIC), supports XOR encryption, and r…☆385Apr 26, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ZigStrike, a powerful Payload Delivery Pipeline developed in Zig, offering a variety of injection techniques and anti-sandbox features.☆528Mar 7, 2026Updated 7 months ago
- Azure Post Exploitation Framework☆247Oct 27, 2025Updated 11 months ago
- ↕️🤫 Stealth redirector for your red team operation security☆1,116Jul 20, 2026Updated 2 months ago
- A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive …☆1,544May 5, 2026Updated 5 months ago
- An executable that simplifies adding the msds-AllowedToActOnBehalfOfOtherIdentity attribute for RBCD☆49Mar 10, 2025Updated last year
- A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike☆244Apr 11, 2026Updated 5 months ago
- Extract and execute a PE embedded within a PNG file using an LNK file.☆476Nov 2, 2024Updated last year
- Two tools written in C that block network traffic for blacklisted EDR processes, using either Windows Defender Firewall (WDF) or Windows …☆305Sep 23, 2025Updated last year
- Red Team scripts to find the permissions assigned to a compromised principal in AWS, GCP, Azure and Kubernetes.☆704Updated this week
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- A python script that automates a C2 Profile build☆49Jul 21, 2026Updated 2 months ago
- .NET assembly loader with patchless AMSI and ETW bypass☆391Apr 19, 2023Updated 3 years ago
- Windows remote execution multitool☆815Mar 25, 2026Updated 6 months ago
- Collection of Beacon Object Files (BOF) for Cobalt Strike☆716Sep 9, 2026Updated last month
- DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely☆395Dec 13, 2024Updated last year
- A Rust implementation of GodPotato — abusing SeImpersonate to gain SYSTEM privileges. Includes a TCP-based reverse shell and indirect NTA…☆370Mar 17, 2026Updated 6 months ago
- Convert your shellcode into an ASCII string☆128Jun 27, 2025Updated last year
- Build sneaky & malicious LNK files.☆162Jul 16, 2025Updated last year
- Advanced Active Directory network topology analyzer with SMB validation, multiple authentication methods (password/NTLM/Kerberos), and co…☆839May 16, 2026Updated 4 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.☆47Aug 5, 2025Updated last year
- Enumerate active EDR's on the system☆154Sep 23, 2025Updated last year
- ☆240Oct 8, 2024Updated 2 years ago
- Cobalt Strike BOF for evasive .NET assembly execution☆328Mar 31, 2025Updated last year
- AppLocker-Based EDR Neutralization☆343Dec 19, 2025Updated 9 months ago
- PoC Exploit for the NTLM reflection SMB flaw.☆719Feb 18, 2026Updated 7 months ago
- RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.☆106Jul 14, 2026Updated 2 months ago