ShadowPhish is an advanced APT awareness toolkit designed to simulate real-world phishing, malware delivery, deepfakes, smishing/vishing, and command & control attacks through an intuitive graphical interface. Perfect for cybersecurity training, red team education, and security awareness programs.
☆246Apr 18, 2025Updated last year
Alternatives and similar repositories for ShadowPhish
Users that are interested in ShadowPhish are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Robust Cobalt Strike shellcode loader with multiple advanced evasion features☆206Apr 21, 2025Updated last year
- Enumerate Domain Users Without Authentication☆306Apr 22, 2025Updated last year
- General Purpose OpSec Server☆114Mar 13, 2026Updated 5 months ago
- Evasion kit for Cobalt Strike☆487Jun 5, 2026Updated 2 months ago
- Dynamic shellcode loader with sophisticated evasion capabilities☆347Oct 1, 2025Updated 10 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Huffman Coding in Shellcode Obfuscation & Dynamic Indirect Syscalls Loader.☆297Apr 6, 2025Updated last year
- A Mythic agent for Windows written in C☆175Updated this week
- smugglo - an easy to use script for wrapping files into self-dropping HTML payloads to bypass content filters☆133Mar 25, 2025Updated last year
- Permanently disable EDRs as local admin☆128Dec 19, 2025Updated 7 months ago
- A tool which bypasses AMSI (AntiMalware Scan Interface) and PowerShell CLM (Constrained Language Mode) and gives you a FullLanguage Power…☆821Mar 28, 2025Updated last year
- Weaponizing DCOM for NTLM Authentication Coercions☆275Jul 1, 2025Updated last year
- ☆49Apr 9, 2025Updated last year
- A user-mode code and its rootkit that will Kill EDR Processes permanently by leveraging the power of Process Creation Blocking Kernel Cal…☆265Jun 10, 2025Updated last year
- ZigStrike, a powerful Payload Delivery Pipeline developed in Zig, offering a variety of injection techniques and anti-sandbox features.☆532Mar 7, 2026Updated 5 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Python3 utility for creating zip files that smuggle additional data for later extraction☆275May 15, 2025Updated last year
- LSASS memory dumper using only NTAPIs, creating a minimal minidump. It can be compiled as shellcode (PIC), supports XOR encryption, and r…☆386Apr 26, 2025Updated last year
- ↕️🤫 Stealth redirector for your red team operation security☆1,100Jul 20, 2026Updated 3 weeks ago
- Azure Post Exploitation Framework☆248Oct 27, 2025Updated 9 months ago
- A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive …☆1,517May 5, 2026Updated 3 months ago
- An executable that simplifies adding the msds-AllowedToActOnBehalfOfOtherIdentity attribute for RBCD☆50Mar 10, 2025Updated last year
- A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike☆238Apr 11, 2026Updated 4 months ago
- ☆657Jul 28, 2026Updated 2 weeks ago
- Extract and execute a PE embedded within a PNG file using an LNK file.☆478Nov 2, 2024Updated last year
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Two tools written in C that block network traffic for blacklisted EDR processes, using either Windows Defender Firewall (WDF) or Windows …☆268Sep 23, 2025Updated 10 months ago
- Windows remote execution multitool☆814Mar 25, 2026Updated 4 months ago
- Enumerate active EDR's on the system☆153Sep 23, 2025Updated 10 months ago
- A Rust implementation of GodPotato — abusing SeImpersonate to gain SYSTEM privileges. Includes a TCP-based reverse shell and indirect NTA…☆368Mar 17, 2026Updated 5 months ago
- A python script that automates a C2 Profile build☆49Jul 21, 2026Updated 3 weeks ago
- .NET assembly loader with patchless AMSI and ETW bypass☆388Apr 19, 2023Updated 3 years ago
- Advanced Active Directory network topology analyzer with SMB validation, multiple authentication methods (password/NTLM/Kerberos), and co…☆825May 16, 2026Updated 3 months ago
- Collection of Beacon Object Files (BOF) for Cobalt Strike☆711Jul 16, 2026Updated last month
- ⚡ SheetStrike - Weaponize Excel files for red team operations. Inject stealthy tracking pixels and NTLMv2 hash capture payloads into XLSX…☆22Dec 23, 2025Updated 7 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely☆393Dec 13, 2024Updated last year
- Convert your shellcode into an ASCII string☆129Jun 27, 2025Updated last year
- Build sneaky & malicious LNK files.☆162Jul 16, 2025Updated last year
- Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.☆46Aug 5, 2025Updated last year
- ☆239Oct 8, 2024Updated last year
- Cobalt Strike BOF for evasive .NET assembly execution☆327Mar 31, 2025Updated last year
- A Cobalt Strike BOF implementation of the SilentHarvest registry dumping technique☆183Apr 14, 2026Updated 4 months ago