Maldev-Academy / MaldevAcademyLdr.2View external linksLinks
RunPE implementation with multiple evasive techniques (2)
☆269Sep 25, 2025Updated 4 months ago
Alternatives and similar repositories for MaldevAcademyLdr.2
Users that are interested in MaldevAcademyLdr.2 are comparing it to the libraries listed below
Sorting:
- Huffman Coding in Shellcode Obfuscation & Dynamic Indirect Syscalls Loader.☆282Apr 6, 2025Updated 10 months ago
- Hijacks code execution via overwriting Control Flow Guard pointers in combase.dll☆135Apr 18, 2025Updated 9 months ago
- Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials☆54May 12, 2025Updated 9 months ago
- Alternative Read and Write primitives using Rtl* functions the unintended way.☆78Aug 25, 2025Updated 5 months ago
- Post-Ex BOF tooling for Hannibal☆24Nov 20, 2024Updated last year
- Boilerplate to develop raw and truly Position Independent Code (PIC).☆116Jan 20, 2025Updated last year
- Stage 0☆169Dec 18, 2024Updated last year
- Stealthily inject shellcode into an executable☆445Oct 19, 2025Updated 3 months ago
- Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials☆61May 12, 2025Updated 9 months ago
- ☆53Sep 23, 2025Updated 4 months ago
- Bypass user-land hooks by syscall tampering via the Trap Flag☆139Aug 25, 2025Updated 5 months ago
- Robust Cobalt Strike shellcode loader with multiple advanced evasion features☆199Apr 21, 2025Updated 9 months ago
- BOF with Synthetic Stackframe☆220Oct 30, 2025Updated 3 months ago
- early cascade injection PoC based on Outflanks blog post☆236Nov 7, 2024Updated last year
- A bunch of shenanigans using functions, VEH and more☆37Jun 8, 2025Updated 8 months ago
- ForsHops☆152Mar 25, 2025Updated 10 months ago
- ☆61Dec 19, 2024Updated last year
- Sleep obfuscation☆265Dec 13, 2024Updated last year
- use python on windows with full submodule support without installation☆30Jan 23, 2025Updated last year
- PE to shellcode☆267Jan 1, 2025Updated last year
- BOF for Kerberos abuse (an implementation of some important features of the Rubeus).☆540Nov 23, 2025Updated 2 months ago
- Cobaltstrike Reflective Loader with Synthetic Stackframe☆182Jan 17, 2026Updated 3 weeks ago
- find dll base addresses without PEB WALK☆157Jul 13, 2025Updated 7 months ago
- Run native PE or .NET executables entirely in-memory. Build the loader as an .exe or .dll—DllMain is Cobalt Strike UDRL-compatible☆266Jun 18, 2025Updated 7 months ago
- Cobalt Strike BOF for evasive .NET assembly execution☆307Mar 31, 2025Updated 10 months ago
- Lateral Movement via Bitlocker DCOM interfaces & COM Hijacking☆433Jun 27, 2025Updated 7 months ago
- Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR …☆296Jul 31, 2024Updated last year
- A new technique that can be used to bypass memory scanners. This can be useful in hiding problematic code (such as reflective loaders imp…☆339Oct 7, 2024Updated last year
- An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer☆539Feb 13, 2024Updated 2 years ago
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆88Jan 2, 2026Updated last month
- Mentally ill EtwTi parser☆66Jan 11, 2026Updated last month
- Locate dlls and function addresses without PEB Walk and EAT parsing☆104Nov 7, 2025Updated 3 months ago
- A Rust implementation of GodPotato — abusing SeImpersonate to gain SYSTEM privileges. Includes a TCP-based reverse shell and indirect NTA…☆355Apr 26, 2025Updated 9 months ago
- Implementing an early exception handler for hooking and threadless process injection without relying on VEH or SEH☆136Aug 31, 2025Updated 5 months ago
- Early Bird Cryo Injections – APC-based DLL & Shellcode Injection via Pre-Frozen Job Objects☆135Apr 6, 2025Updated 10 months ago
- A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.☆128Jan 28, 2026Updated 2 weeks ago
- Webcam capture capability for Cobalt Strike as a BOF, with in-memory download options☆156Mar 26, 2025Updated 10 months ago
- a demo module for the kaine agent to execute and inject assembly modules☆41Aug 28, 2024Updated last year
- PoC module to demonstrate automated lateral movement with the Havoc C2 framework.☆307Dec 9, 2023Updated 2 years ago