A Proof of Concept demonstrating CET-compliant callstack spoofing in Rust. It leverages Windows Thread Pool and Enum Callback trampolining (e.g., EnumSystemLocalesEx) to forge a pristine, hardware-aligned call stack for indirect syscall evasion.
☆59Jul 12, 2026Updated last month
Alternatives and similar repositories for CET-Enum-CallStack-Spoofer
Users that are interested in CET-Enum-CallStack-Spoofer are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A sleepmask based on Ekko that preserves unwind data at sleep time.☆56Mar 30, 2026Updated 5 months ago
- takes shellcode bad-bytes and banishes them, returning cleaned shellcode with preserved functionalities☆63Mar 1, 2026Updated 5 months ago
- open source implementation of the UDC2 spec used in Cobalt Strike☆59Jul 4, 2026Updated last month
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 3 months ago
- BingusLdr is a DLL loader built with Crystal Palace that uses a CET compatible stack spoofing technique.☆112Jul 14, 2026Updated last month
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Cobalt Strike BOF for beacon/shellcode injection using fork & run technique with Draugr synthetic stack frames☆157Nov 23, 2025Updated 9 months ago
- LibPicoManager is a unified PICO management framework that provides centralized control over PICOs in memory, enabling dynamic code loadi…☆43Dec 1, 2025Updated 8 months ago
- Modular User-Defined Reflective Loader (UDRL) built on Crystal Palace for controlled DLL execution and evasion research.☆34Apr 14, 2026Updated 4 months ago
- A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.☆143Jan 28, 2026Updated 7 months ago
- Sleep replacement that executes real, varied work to break behavioral pattern matching by EDR and anti-cheat systems☆78Jul 20, 2026Updated last month
- .NET CLR-Stomping☆149May 20, 2026Updated 3 months ago
- Vectored Exception Handling Squared☆33Dec 27, 2025Updated 8 months ago
- Havoc C2 BOF port of the KslD.sys BYOVD technique. Credential extraction from lsass via physical memory — no OpenProcess, no auditable AP…☆147Apr 22, 2026Updated 4 months ago
- A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike☆241Apr 11, 2026Updated 4 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Moonwalk++: Simple POC Combining StackMoonwalking and Memory Encryption☆233Dec 17, 2025Updated 8 months ago
- Rusty DoublePulsar - Cobalt Strike User-Defined Reflective Loader (UDRL) in Rust (Codename: DoublePulsar)☆119May 14, 2026Updated 3 months ago
- Cobaltstrike Reflective Loader with Synthetic Stackframe☆195Jan 17, 2026Updated 7 months ago
- PoC for generating bthprops.cpl module designed to be loaded by Fsquirt.exe LOLBin☆121Jan 4, 2026Updated 7 months ago
- BOF to run PE in Cobalt Strike Beacon without console creation☆200Nov 23, 2025Updated 9 months ago
- adws enumeration bof☆174Feb 16, 2026Updated 6 months ago
- A PoC UDRL for Cobalt Strike built with Crystal Palace that combines Raphael Mudge's page streaming technique with a modular call gate (D…☆138Jan 21, 2026Updated 7 months ago
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆102Jan 2, 2026Updated 7 months ago
- Transform LDAP filters, BaseDNs, attribute lists, and attribute entries using composable middleware chains. Zero dependencies. Works as a…☆44Apr 13, 2026Updated 4 months ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Using Just In Time (JIT) instruction decryption, this shellcode loader ensures that only the currently executing instruction is visible i…☆67Apr 2, 2025Updated last year
- A BOF that's a BOF Loader and more☆211Apr 6, 2026Updated 4 months ago
- WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.☆129Jun 24, 2026Updated 2 months ago
- Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin res…☆88Jun 20, 2026Updated 2 months ago
- abusing windows toast notifications for fun and user manipulation☆104Jul 11, 2026Updated last month
- PIC shellcode (C/C++) development toolkit designed for malware developers.☆133Dec 23, 2025Updated 8 months ago
- Audiodg.exe DLL hijacking for LPE with reboot-free restart primitive. Executes code as LOCAL SERVICE, escalates to SYSTEM via Scheduled T…☆128Jan 24, 2026Updated 7 months ago
- Self-cleaning in-memory PICO loader for Crystal Palace. Automatically erases traces and operates entirely in memory for stealthy payload …☆58Nov 2, 2025Updated 9 months ago
- Open Source Implementation of Cobalt Strike's Malleable C2☆107Jun 27, 2026Updated 2 months ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- In-memory BOF implementation of Silent Process Exit LSASS dump via RtlReportSilentProcessExit☆19Apr 14, 2026Updated 4 months ago
- Shellcode injection using the Windows Debugging API☆182Jan 4, 2026Updated 7 months ago
- ☆57Jun 28, 2025Updated last year
- sigreturn-oriented(SROP) based sleep obfuscation poc for Linux☆69Dec 15, 2025Updated 8 months ago
- Locate dlls and function addresses without PEB Walk and EAT parsing☆110Nov 7, 2025Updated 9 months ago
- A Cobalt Strike RL built with Crystal Palac; module overloading, NtContinue entry transfer, call stack spoofing, sleep masking, and stati…☆255Mar 15, 2026Updated 5 months ago
- Implementing an early exception handler for hooking and threadless process injection without relying on VEH or SEH☆141Aug 31, 2025Updated 11 months ago