ShadowPhish is an advanced APT awareness toolkit designed to simulate real-world phishing, malware delivery, deepfakes, smishing/vishing, and command & control attacks through an intuitive graphical interface. Perfect for cybersecurity training, red team education, and security awareness programs.
☆245Apr 18, 2025Updated last year
Alternatives and similar repositories for ShadowPhish
Users that are interested in ShadowPhish are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- General Purpose OpSec Server☆114Mar 13, 2026Updated 6 months ago
- Enumerate Domain Users Without Authentication☆311Apr 22, 2025Updated last year
- Evasion kit for Cobalt Strike☆500Jun 5, 2026Updated 3 months ago
- Dynamic shellcode loader with sophisticated evasion capabilities☆343Oct 1, 2025Updated 11 months ago
- Huffman Coding in Shellcode Obfuscation & Dynamic Indirect Syscalls Loader.☆308Apr 6, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A Mythic agent for Windows written in C☆181Aug 22, 2026Updated 3 weeks ago
- smugglo - an easy to use script for wrapping files into self-dropping HTML payloads to bypass content filters☆133Mar 25, 2025Updated last year
- A tool which bypasses AMSI (AntiMalware Scan Interface) and PowerShell CLM (Constrained Language Mode) and gives you a FullLanguage Power…☆820Mar 28, 2025Updated last year
- Weaponizing DCOM for NTLM Authentication Coercions☆274Jul 1, 2025Updated last year
- ☆49Apr 9, 2025Updated last year
- A user-mode code and its rootkit that will Kill EDR Processes permanently by leveraging the power of Process Creation Blocking Kernel Cal…☆265Jun 10, 2025Updated last year
- Permanently disable EDRs as local admin☆130Dec 19, 2025Updated 9 months ago
- Python3 utility for creating zip files that smuggle additional data for later extraction☆275May 15, 2025Updated last year
- LSASS memory dumper using only NTAPIs, creating a minimal minidump. It can be compiled as shellcode (PIC), supports XOR encryption, and r…☆385Apr 26, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ZigStrike, a powerful Payload Delivery Pipeline developed in Zig, offering a variety of injection techniques and anti-sandbox features.☆529Mar 7, 2026Updated 6 months ago
- Azure Post Exploitation Framework☆248Oct 27, 2025Updated 10 months ago
- ↕️🤫 Stealth redirector for your red team operation security☆1,108Jul 20, 2026Updated last month
- A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive …☆1,542May 5, 2026Updated 4 months ago
- An executable that simplifies adding the msds-AllowedToActOnBehalfOfOtherIdentity attribute for RBCD☆49Mar 10, 2025Updated last year
- A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike☆241Apr 11, 2026Updated 5 months ago
- Extract and execute a PE embedded within a PNG file using an LNK file.☆476Nov 2, 2024Updated last year
- Two tools written in C that block network traffic for blacklisted EDR processes, using either Windows Defender Firewall (WDF) or Windows …☆267Sep 23, 2025Updated 11 months ago
- ☆659Updated this week
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A python script that automates a C2 Profile build☆49Jul 21, 2026Updated last month
- .NET assembly loader with patchless AMSI and ETW bypass☆388Apr 19, 2023Updated 3 years ago
- Windows remote execution multitool☆815Mar 25, 2026Updated 5 months ago
- Collection of Beacon Object Files (BOF) for Cobalt Strike☆712Sep 9, 2026Updated last week
- DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely☆396Dec 13, 2024Updated last year
- A Rust implementation of GodPotato — abusing SeImpersonate to gain SYSTEM privileges. Includes a TCP-based reverse shell and indirect NTA…☆369Mar 17, 2026Updated 6 months ago
- Convert your shellcode into an ASCII string☆128Jun 27, 2025Updated last year
- Build sneaky & malicious LNK files.☆161Jul 16, 2025Updated last year
- Advanced Active Directory network topology analyzer with SMB validation, multiple authentication methods (password/NTLM/Kerberos), and co…☆837May 16, 2026Updated 4 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.☆46Aug 5, 2025Updated last year
- Enumerate active EDR's on the system☆153Sep 23, 2025Updated 11 months ago
- ☆241Oct 8, 2024Updated last year
- Cobalt Strike BOF for evasive .NET assembly execution☆326Mar 31, 2025Updated last year
- AppLocker-Based EDR Neutralization☆342Dec 19, 2025Updated 9 months ago
- PoC Exploit for the NTLM reflection SMB flaw.☆716Feb 18, 2026Updated 7 months ago
- RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.☆105Jul 14, 2026Updated 2 months ago