PoC for a Havoc agent/handler setup with all C2 traffic routed through GitHub. No direct connections: all commands and responses are relayed through Issues and Comments for maximum stealth.
☆47Jul 9, 2025Updated last year
Alternatives and similar repositories for HavocHub
Users that are interested in HavocHub are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- VolchockC2 is a custom-built Command & Control (C2) framework, currently under active development. Designed for red team operations and a…☆36Jul 31, 2025Updated last year
- Self Cleanup in post-ex job☆58Sep 10, 2024Updated 2 years ago
- Obfuscate the bytes of your payload with an association dictionary☆77Nov 7, 2025Updated 10 months ago
- inspired by mr d0x filefix☆16Feb 4, 2026Updated 7 months ago
- Beacon Object File (BOF) for Windows Session Hijacking via IHxHelpPaneServer COM☆71Dec 25, 2025Updated 8 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Whitepaper☆16Dec 1, 2025Updated 9 months ago
- Thats it! An Open-Source Windows UEFI Rootkit☆41Jul 19, 2025Updated last year
- Rust implementation of phantom persistence technique documented in https://blog.phantomsec.tools/phantom-persistence☆66Jun 23, 2025Updated last year
- ☆50Dec 5, 2025Updated 9 months ago
- Two tools written in C that block network traffic for blacklisted EDR processes, using either Windows Defender Firewall (WDF) or Windows …☆267Sep 23, 2025Updated 11 months ago
- Loading Fileless Remote PE from URI to memory with argument passing and ETW patching and NTDLL unhooking and No New Thread technique☆77Sep 29, 2022Updated 3 years ago
- shellcode transformation tool for YARA evasion☆62Dec 17, 2025Updated 9 months ago
- DRILL (Distributable Remote Integrated Lightweight Link) is a powerful and stealthy Command and Control (C2) framework designed for seaml…☆38Jul 31, 2025Updated last year
- Run PowerShell command without invoking powershell.exe☆27Apr 9, 2026Updated 5 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Cobalt Strike Beacon Object File (BOF) that obtain SYSTEM privilege with SeImpersonate privilege by passing a malicious IUnknwon object t…☆13Feb 4, 2024Updated 2 years ago
- tsh多终端代理通信☆20Feb 26, 2025Updated last year
- Cobalt Strike BOF for beacon/shellcode injection using fork & run technique with Draugr synthetic stack frames☆156Nov 23, 2025Updated 9 months ago
- ZoomBotC2 is a stealthy Command and Control (C2) framework that leverages Zoom's API endpoints for covert communication between implants …☆57Jun 30, 2025Updated last year
- Local SYSTEM auth trigger for relaying - X☆160Jul 23, 2025Updated last year
- Python based tool for generating Shellcode from PIC C☆43Nov 6, 2025Updated 10 months ago
- A Cobalt Strike payload generator and lateral movement aggressor script which places Beacon shellcode into a custom shellcode loader☆45Sep 25, 2024Updated last year
- Beacon Object File to delete token privileges and lower the integrity level to untrusted for a specified process☆44Jun 15, 2022Updated 4 years ago
- ☆62Feb 12, 2026Updated 7 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard histor…☆117Apr 16, 2026Updated 5 months ago
- Cobaltstrike Reflective Loader with Synthetic Stackframe☆193Jan 17, 2026Updated 8 months ago
- Novel Windows process injection: assembles existing open handles (process & thread), natural RWX regions, and special user APC (NtQueueAp…☆74Feb 17, 2026Updated 7 months ago
- C# code to run PIC using CreateThread☆17Apr 19, 2019Updated 7 years ago
- CSharp reimplementation of Venoma, another C++ Cobalt Strike beacon dropper with custom indirect syscalls execution☆51Apr 22, 2024Updated 2 years ago
- Havoc 3rd party agent. Designed to be evasive. Fully PIC shellcode agent.☆17Dec 29, 2022Updated 3 years ago
- This tool helps inject code into the processes of Antivirus programs.☆190May 23, 2026Updated 3 months ago
- BOF to run PE in Cobalt Strike Beacon without console creation☆198Nov 23, 2025Updated 9 months ago
- This technique leverages PowerShell's .NET interop layer and COM automation to achieve stealthy command execution by abusing implicit typ…☆54May 16, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆317Aug 31, 2026Updated 2 weeks ago
- ☆90May 15, 2024Updated 2 years ago
- 2 PE Loader tools that load a PE from memory, decrypt it and make some magic things to execute seamlessly from memory☆56May 20, 2026Updated 3 months ago
- Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.☆46Aug 5, 2025Updated last year
- Hides in your attic... I mean process☆26Apr 29, 2026Updated 4 months ago
- yublueflower is a security workflow to discover real-world threats using open-source tools such as urlfinder, katana, httpx, nuclei, and …☆22Sep 7, 2026Updated last week
- Locate dlls and function addresses without PEB Walk and EAT parsing☆109Nov 7, 2025Updated 10 months ago