PoC for a Havoc agent/handler setup with all C2 traffic routed through GitHub. No direct connections: all commands and responses are relayed through Issues and Comments for maximum stealth.
☆46Jul 9, 2025Updated last year
Alternatives and similar repositories for HavocHub
Users that are interested in HavocHub are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- VolchockC2 is a custom-built Command & Control (C2) framework, currently under active development. Designed for red team operations and a…☆35Jul 31, 2025Updated 11 months ago
- Beacon Object File (BOF) for Windows Session Hijacking via IHxHelpPaneServer COM☆71Dec 25, 2025Updated 6 months ago
- Self Cleanup in post-ex job☆59Sep 10, 2024Updated last year
- inspired by mr d0x filefix☆16Feb 4, 2026Updated 5 months ago
- Obfuscate the bytes of your payload with an association dictionary☆78Nov 7, 2025Updated 8 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Whitepaper☆15Dec 1, 2025Updated 7 months ago
- Thats it! An Open-Source Windows UEFI Rootkit☆39Jul 19, 2025Updated last year
- Rust implementation of phantom persistence technique documented in https://blog.phantomsec.tools/phantom-persistence☆65Jun 23, 2025Updated last year
- ☆50Dec 5, 2025Updated 7 months ago
- Two tools written in C that block network traffic for blacklisted EDR processes, using either Windows Defender Firewall (WDF) or Windows …☆268Sep 23, 2025Updated 9 months ago
- This technique leverages PowerShell's .NET interop layer and COM automation to achieve stealthy command execution by abusing implicit typ…☆54May 16, 2025Updated last year
- Loading Fileless Remote PE from URI to memory with argument passing and ETW patching and NTDLL unhooking and No New Thread technique☆77Sep 29, 2022Updated 3 years ago
- Novel Windows process injection: assembles existing open handles (process & thread), natural RWX regions, and special user APC (NtQueueAp…☆74Feb 17, 2026Updated 5 months ago
- An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard histor…☆114Apr 16, 2026Updated 3 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- One-header configurable C++20 COFF loader☆21Jul 21, 2025Updated last year
- DRILL (Distributable Remote Integrated Lightweight Link) is a powerful and stealthy Command and Control (C2) framework designed for seaml…☆38Jul 31, 2025Updated 11 months ago
- shellcode transformation tool for YARA evasion☆62Dec 17, 2025Updated 7 months ago
- Run PowerShell command without invoking powershell.exe☆27Apr 9, 2026Updated 3 months ago
- Parses logs created by Cobalt Strike, Brute Ratel, OC2 and creates an SQLite DB which can be used to create custom reports.☆31Jul 4, 2026Updated 2 weeks ago
- Cobalt Strike Beacon Object File (BOF) that obtain SYSTEM privilege with SeImpersonate privilege by passing a malicious IUnknwon object t…☆13Feb 4, 2024Updated 2 years ago
- ZoomBotC2 is a stealthy Command and Control (C2) framework that leverages Zoom's API endpoints for covert communication between implants …☆57Jun 30, 2025Updated last year
- Smuggling C2 comms through links previews☆18Jun 17, 2026Updated last month
- Local SYSTEM auth trigger for relaying - X☆159Jul 23, 2025Updated 11 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Cobalt Strike BOF for beacon/shellcode injection using fork & run technique with Draugr synthetic stack frames☆156Nov 23, 2025Updated 7 months ago
- Python based tool for generating Shellcode from PIC C☆43Nov 6, 2025Updated 8 months ago
- This tool helps inject code into the processes of Antivirus programs.☆189May 23, 2026Updated last month
- A Cobalt Strike payload generator and lateral movement aggressor script which places Beacon shellcode into a custom shellcode loader☆46Sep 25, 2024Updated last year
- Beacon Object File to delete token privileges and lower the integrity level to untrusted for a specified process☆46Jun 15, 2022Updated 4 years ago
- ☆62Feb 12, 2026Updated 5 months ago
- Cobaltstrike Reflective Loader with Synthetic Stackframe☆193Jan 17, 2026Updated 6 months ago
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆311Jul 5, 2026Updated 2 weeks ago
- C# code to run PIC using CreateThread☆17Apr 19, 2019Updated 7 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- CSharp reimplementation of Venoma, another C++ Cobalt Strike beacon dropper with custom indirect syscalls execution☆51Apr 22, 2024Updated 2 years ago
- Havoc 3rd party agent. Designed to be evasive. Fully PIC shellcode agent.☆17Dec 29, 2022Updated 3 years ago
- Robust Cobalt Strike shellcode loader with multiple advanced evasion features☆206Apr 21, 2025Updated last year
- BOF to run PE in Cobalt Strike Beacon without console creation☆199Nov 23, 2025Updated 7 months ago
- ☆91May 15, 2024Updated 2 years ago
- BeaconatorC2 is a framework for red teaming and adversarial emulation, providing a full-featured management interface, along with a catal…☆95May 25, 2026Updated last month
- Hooking KPRCB IdlePreselect function to gain execution inside PID 0.☆81Apr 13, 2025Updated last year