𦫠| GoRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team, with a specific focus on the Go programming language, all is made for educational purpoeses only.
β676Apr 27, 2025Updated last year
Alternatives and similar repositories for GoRedOps
Users that are interested in GoRedOps are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONβ¦β856Dec 10, 2025Updated 8 months ago
- Remote Kerberos Relay made easy! Advanced Kerberos Relay Frameworkβ649May 8, 2025Updated last year
- Golang weaponization for red teamers.β525Jan 17, 2024Updated 2 years ago
- Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR β¦β315Jul 31, 2024Updated 2 years ago
- Dump cookies and credentials directly from Chrome/Edge process memoryβ1,496Apr 9, 2026Updated 4 months ago
- 1-Click AI Models by DigitalOcean Gradient β’ AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Shellcode loader generator with multiples featuresβ511Dec 31, 2024Updated last year
- Windows remote execution multitoolβ815Mar 25, 2026Updated 5 months ago
- NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-buiβ¦β242Feb 12, 2025Updated last year
- Because AV evasion should be easy.β901Nov 28, 2024Updated last year
- Repository for advanced Red Team techniques focused on Rustβ1,900Dec 29, 2025Updated 8 months ago
- Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird β¦β809Jan 26, 2026Updated 7 months ago
- Tool to remotely dump secrets from the Windows registryβ535Jul 6, 2026Updated last month
- A beacon object file implementation of PoolParty Process Injection Technique.β458Dec 21, 2023Updated 2 years ago
- find dll base addresses without PEB WALKβ170Jul 13, 2025Updated last year
- Open source password manager - Proton Pass β’ AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Two new offensive techniques using Windows Fibers: PoisonFiber (The first remote enumeration & Fiber injection capability POC tool) Phanβ¦β286Sep 18, 2024Updated last year
- A Go implementation of Cobalt Strike style BOF/COFF loaders.β286Jun 24, 2026Updated 2 months ago
- A BOF that runs unmanaged PEs inlineβ702Oct 23, 2024Updated last year
- Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!β588Aug 17, 2026Updated 2 weeks ago
- An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layerβ554Feb 13, 2024Updated 2 years ago
- βοΈπ€« Stealth redirector for your red team operation securityβ1,104Jul 20, 2026Updated last month
- A command and control framework written in rust.β390Aug 12, 2026Updated 2 weeks ago
- HVNC for Cobalt Strikeβ1,343Dec 7, 2023Updated 2 years ago
- BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactionsβ361Nov 19, 2024Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer β’ AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).β604Mar 19, 2024Updated 2 years ago
- Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetryβ478Aug 2, 2024Updated 2 years ago
- Shellcode encryptor & obfuscator toolβ1,038Jul 21, 2026Updated last month
- Simulate the behavior of AV/EDR for malware development training.β567Feb 15, 2024Updated 2 years ago
- LSASS memory dumper using only NTAPIs, creating a minimal minidump. It can be compiled as shellcode (PIC), supports XOR encryption, and rβ¦β387Apr 26, 2025Updated last year
- A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.β638Jan 2, 2025Updated last year
- β91May 15, 2024Updated 2 years ago
- Stage 0β171Dec 18, 2024Updated last year
- A modern 32/64-bit position independent implant templateβ1,364Jun 1, 2026Updated 2 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits β’ AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Collection of UAC Bypass Techniques Weaponized as BOFsβ656Feb 21, 2024Updated 2 years ago
- SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.β1,221Apr 16, 2025Updated last year
- Reuse open handles to dynamically dump LSASS.β246Apr 4, 2024Updated 2 years ago
- A list of python tools to help create an OPSEC-safe Cobalt Strike profile.β540Jun 12, 2026Updated 2 months ago
- Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.β327Apr 12, 2024Updated 2 years ago
- Sleep obfuscationβ276Dec 13, 2024Updated last year
- PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.β614Jan 20, 2026Updated 7 months ago