🦫 | GoRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team, with a specific focus on the Go programming language, all is made for educational purpoeses only.
☆670Apr 27, 2025Updated last year
Alternatives and similar repositories for GoRedOps
Users that are interested in GoRedOps are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ON…☆856Dec 10, 2025Updated 10 months ago
- Remote Kerberos Relay made easy! Advanced Kerberos Relay Framework☆651May 8, 2025Updated last year
- Golang weaponization for red teamers.☆526Jan 17, 2024Updated 2 years ago
- Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR …☆311Jul 31, 2024Updated 2 years ago
- Dump cookies and credentials directly from Chrome/Edge process memory☆1,502Apr 9, 2026Updated 6 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Shellcode loader generator with multiples features☆509Dec 31, 2024Updated last year
- Windows remote execution multitool☆815Mar 25, 2026Updated 6 months ago
- NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-bui…☆243Feb 12, 2025Updated last year
- Because AV evasion should be easy.☆907Nov 28, 2024Updated last year
- Repository for advanced Red Team techniques focused on Rust☆1,904Dec 29, 2025Updated 9 months ago
- Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird …☆809Jan 26, 2026Updated 8 months ago
- Tool to remotely dump secrets from the Windows registry☆537Jul 6, 2026Updated 3 months ago
- A beacon object file implementation of PoolParty Process Injection Technique.☆458Dec 21, 2023Updated 2 years ago
- find dll base addresses without PEB WALK☆169Jul 13, 2025Updated last year
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!☆610Aug 17, 2026Updated last month
- Two new offensive techniques using Windows Fibers: PoisonFiber (The first remote enumeration & Fiber injection capability POC tool) Phan…☆302Sep 18, 2024Updated 2 years ago
- A Go implementation of Cobalt Strike style BOF/COFF loaders.☆285Jun 24, 2026Updated 3 months ago
- A BOF that runs unmanaged PEs inline☆700Oct 23, 2024Updated last year
- An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer☆556Feb 13, 2024Updated 2 years ago
- A command and control framework written in rust.☆389Aug 12, 2026Updated last month
- ↕️🤫 Stealth redirector for your red team operation security☆1,117Jul 20, 2026Updated 2 months ago
- HVNC for Cobalt Strike☆1,347Dec 7, 2023Updated 2 years ago
- BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions☆360Nov 19, 2024Updated last year
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).☆606Mar 19, 2024Updated 2 years ago
- Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry☆477Aug 2, 2024Updated 2 years ago
- LSASS memory dumper using only NTAPIs, creating a minimal minidump. It can be compiled as shellcode (PIC), supports XOR encryption, and r…☆385Apr 26, 2025Updated last year
- Simulate the behavior of AV/EDR for malware development training.☆565Feb 15, 2024Updated 2 years ago
- Shellcode encryptor & obfuscator tool☆1,047Jul 21, 2026Updated 2 months ago
- A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.☆640Jan 2, 2025Updated last year
- ☆90May 15, 2024Updated 2 years ago
- Stage 0☆169Dec 18, 2024Updated last year
- A modern 32/64-bit position independent implant template☆1,373Jun 1, 2026Updated 4 months ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- Collection of UAC Bypass Techniques Weaponized as BOFs☆662Feb 21, 2024Updated 2 years ago
- Reuse open handles to dynamically dump LSASS.☆245Apr 4, 2024Updated 2 years ago
- SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.☆1,225Sep 29, 2026Updated last week
- A list of python tools to help create an OPSEC-safe Cobalt Strike profile.☆546Jun 12, 2026Updated 3 months ago
- Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.☆324Apr 12, 2024Updated 2 years ago
- Sleep obfuscation☆275Dec 13, 2024Updated last year
- PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.☆629Jan 20, 2026Updated 8 months ago