PoC for a Havoc agent/handler setup with all C2 traffic routed through GitHub. No direct connections: all commands and responses are relayed through Issues and Comments for maximum stealth.
☆47Jul 9, 2025Updated last year
Alternatives and similar repositories for HavocHub
Users that are interested in HavocHub are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- VolchockC2 is a custom-built Command & Control (C2) framework, currently under active development. Designed for red team operations and a…☆36Jul 31, 2025Updated last year
- Self Cleanup in post-ex job☆58Sep 10, 2024Updated 2 years ago
- Obfuscate the bytes of your payload with an association dictionary☆77Nov 7, 2025Updated 11 months ago
- inspired by mr d0x filefix☆16Feb 4, 2026Updated 8 months ago
- Beacon Object File (BOF) for Windows Session Hijacking via IHxHelpPaneServer COM☆72Dec 25, 2025Updated 9 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Whitepaper☆16Dec 1, 2025Updated 10 months ago
- Thats it! An Open-Source Windows UEFI Rootkit☆41Jul 19, 2025Updated last year
- Rust implementation of phantom persistence technique documented in https://blog.phantomsec.tools/phantom-persistence☆67Jun 23, 2025Updated last year
- ☆49Dec 5, 2025Updated 10 months ago
- Two tools written in C that block network traffic for blacklisted EDR processes, using either Windows Defender Firewall (WDF) or Windows …☆305Sep 23, 2025Updated last year
- Loading Fileless Remote PE from URI to memory with argument passing and ETW patching and NTDLL unhooking and No New Thread technique☆77Sep 29, 2022Updated 4 years ago
- shellcode transformation tool for YARA evasion☆62Sep 20, 2026Updated 2 weeks ago
- DRILL (Distributable Remote Integrated Lightweight Link) is a powerful and stealthy Command and Control (C2) framework designed for seaml…☆37Jul 31, 2025Updated last year
- Run PowerShell command without invoking powershell.exe☆27Apr 9, 2026Updated 6 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Cobalt Strike Beacon Object File (BOF) that obtain SYSTEM privilege with SeImpersonate privilege by passing a malicious IUnknwon object t…☆12Feb 4, 2024Updated 2 years ago
- tsh多终端代理通信☆20Feb 26, 2025Updated last year
- Cobalt Strike BOF for beacon/shellcode injection using fork & run technique with Draugr synthetic stack frames☆157Nov 23, 2025Updated 10 months ago
- ZoomBotC2 is a stealthy Command and Control (C2) framework that leverages Zoom's API endpoints for covert communication between implants …☆57Jun 30, 2025Updated last year
- Local SYSTEM auth trigger for relaying - X☆160Jul 23, 2025Updated last year
- Python based tool for generating Shellcode from PIC C☆43Nov 6, 2025Updated 11 months ago
- A Cobalt Strike payload generator and lateral movement aggressor script which places Beacon shellcode into a custom shellcode loader☆44Sep 25, 2024Updated 2 years ago
- Beacon Object File to delete token privileges and lower the integrity level to untrusted for a specified process☆43Jun 15, 2022Updated 4 years ago
- ☆61Feb 12, 2026Updated 7 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard histor…☆116Apr 16, 2026Updated 5 months ago
- Cobaltstrike Reflective Loader with Synthetic Stackframe☆192Jan 17, 2026Updated 8 months ago
- Novel Windows process injection: assembles existing open handles (process & thread), natural RWX regions, and special user APC (NtQueueAp…☆77Feb 17, 2026Updated 7 months ago
- C# code to run PIC using CreateThread☆17Apr 19, 2019Updated 7 years ago
- CSharp reimplementation of Venoma, another C++ Cobalt Strike beacon dropper with custom indirect syscalls execution☆51Apr 22, 2024Updated 2 years ago
- Havoc 3rd party agent. Designed to be evasive. Fully PIC shellcode agent.☆17Dec 29, 2022Updated 3 years ago
- This tool helps inject code into the processes of Antivirus programs.☆190May 23, 2026Updated 4 months ago
- BOF to run PE in Cobalt Strike Beacon without console creation☆197Nov 23, 2025Updated 10 months ago
- This technique leverages PowerShell's .NET interop layer and COM automation to achieve stealthy command execution by abusing implicit typ…☆54May 16, 2025Updated last year
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆318Aug 31, 2026Updated last month
- ☆90May 15, 2024Updated 2 years ago
- 2 PE Loader tools that load a PE from memory, decrypt it and make some magic things to execute seamlessly from memory☆56May 20, 2026Updated 4 months ago
- Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.☆47Aug 5, 2025Updated last year
- Hides in your attic... I mean process☆26Apr 29, 2026Updated 5 months ago
- yublueflower is a security workflow to discover real-world threats using open-source tools such as urlfinder, katana, httpx, nuclei, and …☆22Updated this week
- Locate dlls and function addresses without PEB Walk and EAT parsing☆109Nov 7, 2025Updated 11 months ago