Clean Indirect Syscalls with Hook Evasion & Return Address Spoofing.
☆101Apr 30, 2026Updated 4 months ago
Alternatives and similar repositories for DoomSyscalls
Users that are interested in DoomSyscalls are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- BingusLdr is a DLL loader built with Crystal Palace that uses a CET compatible stack spoofing technique.☆114Jul 14, 2026Updated 2 months ago
- Locate dlls and function addresses without PEB Walk and EAT parsing☆109Nov 7, 2025Updated 10 months ago
- A EDR bypassing shellcode loader framework for Windows 10 64bit, featuring ETW/AMSI patching, Tartarus Gate, process protection and more☆95Jun 24, 2026Updated 3 months ago
- Polymorphic PE rewriter for Windows x64 , rewrites binaries into semantically identical but byte-different variants☆200Jun 6, 2026Updated 3 months ago
- A collection of DPAPI hunting and parsing BOFs☆39Mar 3, 2026Updated 6 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆28May 21, 2026Updated 4 months ago
- ☆89Sep 3, 2026Updated 3 weeks ago
- Evade behavioral analysis by executing malicious code within trusted Microsoft call stacks, patchless hooking library IAT/EAT.☆148Dec 8, 2025Updated 9 months ago
- Evasive loader for .NET Framework assemblies☆83May 12, 2026Updated 4 months ago
- ☆69Jul 12, 2026Updated 2 months ago
- COM Windows Persistence Technique☆89Apr 27, 2026Updated 4 months ago
- Technical Reference to multiple relay techniques☆193May 21, 2026Updated 4 months ago
- A Crystal Palace shared library to resolve & perform syscalls☆65Oct 29, 2025Updated 10 months ago
- Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin res…☆88Jun 20, 2026Updated 3 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Using Just In Time (JIT) instruction decryption, this shellcode loader ensures that only the currently executing instruction is visible i…☆68Apr 2, 2025Updated last year
- Sleep replacement that executes real, varied work to break behavioral pattern matching by EDR and anti-cheat systems☆84Jul 20, 2026Updated 2 months ago
- A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Slee…☆110Jul 26, 2026Updated last month
- Evasion kit for Cobalt Strike☆30Jan 16, 2026Updated 8 months ago
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆26May 10, 2026Updated 4 months ago
- ☆32May 19, 2026Updated 4 months ago
- SafeHarbor revamped with Direct Syscalls using InlineWhispers3☆14Feb 16, 2026Updated 7 months ago
- ☆76Dec 19, 2024Updated last year
- Atomic test units for BOF execution☆60Apr 26, 2026Updated 4 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆72Apr 20, 2026Updated 5 months ago
- A PoC UDRL for Cobalt Strike built with Crystal Palace that combines Raphael Mudge's page streaming technique with a modular call gate (D…☆139Jan 21, 2026Updated 8 months ago
- Implementing Ghostly-Hollowing using tampered syscalls for remote PE injection☆75Dec 26, 2025Updated 8 months ago
- out-of-tree LLVM 21+ pass plugin for policy-driven IR obfuscation.☆108Updated this week
- RunPE implementation with multiple evasive techniques (2)☆285Sep 25, 2025Updated 11 months ago
- Self-cleaning in-memory PICO loader for Crystal Palace. Automatically erases traces and operates entirely in memory for stealthy payload …☆59Nov 2, 2025Updated 10 months ago
- Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.☆90Jun 15, 2026Updated 3 months ago
- Code execution/injection technique using DLL PEB module structure manipulation☆287Jun 4, 2025Updated last year
- ☆216Sep 11, 2026Updated last week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 4 months ago
- ☆88Feb 12, 2026Updated 7 months ago
- WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.☆131Jun 24, 2026Updated 2 months ago
- Rusty DoublePulsar - Cobalt Strike User-Defined Reflective Loader (UDRL) in Rust (Codename: DoublePulsar)☆117May 14, 2026Updated 4 months ago
- psexec-like remote execution using the paexec wire protocol that supports paexec and remoteexecm2 from manageengine adselfservice plus☆44Mar 24, 2026Updated 6 months ago
- BOF POC of the DSCourier project / invoking WinGet via COM☆90Apr 23, 2026Updated 5 months ago
- A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.☆144Jan 28, 2026Updated 7 months ago