The first open source runtime windows batch and command line deobfuscator
☆50Jun 23, 2026Updated last month
Alternatives and similar repositories for Exorcism
Users that are interested in Exorcism are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A runtime Assembly dumper for powershell to combat the rise in .net based crypters and malware.☆18Aug 26, 2025Updated 11 months ago
- A Free Open sourced crypter that builds a output .NET .exe Stub (Updated whenever I feel like it)☆22Oct 18, 2025Updated 9 months ago
- Querying And Deleting Shadow Copies Using The IOCTL_VOLSNAP_QUERY_NAMES_OF_SNAPSHOTS & IOCTL_VOLSNAP_DELETE_SNAPSHOT IOCTLs☆22Aug 7, 2025Updated 11 months ago
- The best powershell obfuscator ever made☆136Jun 16, 2026Updated last month
- A simple Reset Survival PoC☆15Jan 25, 2026Updated 6 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- PandaCrypter is a C#-based tool designed to convert PowerShell scripts into obfuscated batch files (.bat) with encryption and additional …☆52Aug 16, 2025Updated 11 months ago
- Shellcode capable of bypassing EAF / IAF mitigations☆30Apr 11, 2023Updated 3 years ago
- Binary Ninja plugin to deobfuscate strings obfuscated with the Garble project☆45Mar 6, 2025Updated last year
- Implementation of KlezVirus' silent moonwalk approach for payloads☆18Feb 13, 2026Updated 5 months ago
- Havoc Professional backend plugin to allow ingesting of events and logs to Ghostwriter☆16Feb 25, 2026Updated 5 months ago
- Overlord☆167Updated this week
- Anti-Debugging (Self-Debugging)☆17Sep 6, 2025Updated 10 months ago
- VDM sig bypass and additional WinAPI stubs☆19Feb 16, 2026Updated 5 months ago
- Print the stack trace☆51Mar 8, 2026Updated 4 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A lightweight Command and Control (C2) framework built for offensive security research and red teaming (Post Exploitation).☆68Dec 17, 2025Updated 7 months ago
- Patches the AmsiScan function in clr.dll allowing for unrestricted assembly loading in .NET☆54May 5, 2025Updated last year
- Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials☆61May 12, 2025Updated last year
- proper ntdll .text section unhooking via native api. unlike other unhookers this doesnt leave 2 ntdlls loaded. x86/x64/wow64 supported.☆54Dec 9, 2025Updated 7 months ago
- Next-Gen Stealer written in Go. Stealing from Chromium-Based & Firefox-Based Browsers, Crypto Wallets and more, from every user on every …☆26Jul 15, 2026Updated last week
- ShadowDropper is a utility for covertly delivering and executing payloads on a target system.☆27Jul 4, 2025Updated last year
- Most advanced and poorly coded windows batch obfuscator ever made (aka the best)☆355Dec 1, 2025Updated 7 months ago
- Havoc 3rd party agent. Designed to be evasive. Fully PIC shellcode agent.☆17Dec 29, 2022Updated 3 years ago
- Windows stealer written in Rust, focused on minimal dependencies and maximum efficiency. It uses mostly direct Windows API calls, avoidin…☆81Oct 10, 2025Updated 9 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- PPLReaper is a Windows UNSIGNED kernel driver + userland companion tool designed to inspect and manipulate Protected Process Light (PPL) …☆24Mar 4, 2026Updated 4 months ago
- [WIP] A Modern Rust Remote Administration Tool for Windows.☆71May 19, 2026Updated 2 months ago
- ☆36Jul 1, 2025Updated last year
- Command and Control Framework using powershell implants☆36Jun 17, 2025Updated last year
- golang decryption poc of the new app bound encryption introduced in chrome version 127.☆21Nov 4, 2024Updated last year
- Reverse engineering malware samples☆16Dec 3, 2021Updated 4 years ago
- Dump LSASS via physical memory read primitives in vulnerable kernel drivers☆35Updated this week
- Utilizing DLang For Offensive Operations.☆15May 29, 2025Updated last year
- Bootloader for Nuitka-compiled Python DLLs. Loads main.dll extracted via nuitka-extractor directly from third-party apps. Lightweight C i…☆16Nov 29, 2025Updated 7 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- SharpSilentChrome is a C# project that "silently" installs browser extensions on Google Chrome or MS Edge by updating the browsers' Prefe…☆202Mar 19, 2026Updated 4 months ago
- A tool written in golang which compress using UPX and patch it with the provided PE file to make "UPX -d" flag impossible to decompress a…☆30Jan 2, 2025Updated last year
- A C# PE loader for x64 and x86 PE files.☆56Mar 9, 2026Updated 4 months ago
- An example of an external LLVM plugin module transform pass for the latest versions.☆15Oct 21, 2025Updated 9 months ago
- Perfect way to spoof SMBios serials before bootx64.efi ( UEFI )☆17May 14, 2025Updated last year
- Near compile-time string obfuscation for Golang☆13Oct 3, 2023Updated 2 years ago
- process hollowing variant using NtCreateSection + NtMapViewOfSection + ResumeThread☆31Jan 9, 2022Updated 4 years ago