Clean Indirect Syscalls with Hook Evasion & Return Address Spoofing.
☆100Apr 30, 2026Updated 2 months ago
Alternatives and similar repositories for DoomSyscalls
Users that are interested in DoomSyscalls are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- BingusLdr is a DLL loader built with Crystal Palace that uses a CET compatible stack spoofing technique.☆109Jul 14, 2026Updated last week
- Locate dlls and function addresses without PEB Walk and EAT parsing☆110Nov 7, 2025Updated 8 months ago
- BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation☆132Mar 27, 2026Updated 3 months ago
- A EDR bypassing shellcode loader framework for Windows 10 64bit, featuring ETW/AMSI patching, Tartarus Gate, process protection and more☆83Jun 24, 2026Updated last month
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆27May 21, 2026Updated 2 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Polymorphic PE rewriter for Windows x64 , rewrites binaries into semantically identical but byte-different variants☆197Jun 6, 2026Updated last month
- ☆86Apr 8, 2026Updated 3 months ago
- A collection of DPAPI hunting and parsing BOFs☆38Mar 3, 2026Updated 4 months ago
- Evade behavioral analysis by executing malicious code within trusted Microsoft call stacks, patchless hooking library IAT/EAT.☆146Dec 8, 2025Updated 7 months ago
- Evasive loader for .NET Framework assemblies☆82May 12, 2026Updated 2 months ago
- COM Windows Persistence Technique☆90Apr 27, 2026Updated 2 months ago
- ☆53Jul 12, 2026Updated last week
- Technical Reference to multiple relay techniques☆191May 21, 2026Updated 2 months ago
- ☆23May 19, 2026Updated 2 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Sleep replacement that executes real, varied work to break behavioral pattern matching by EDR and anti-cheat systems☆34Updated this week
- Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin res…☆87Jun 20, 2026Updated last month
- A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Slee…☆72Jul 11, 2026Updated 2 weeks ago
- A Crystal Palace shared library to resolve & perform syscalls☆61Oct 29, 2025Updated 8 months ago
- Using Just In Time (JIT) instruction decryption, this shellcode loader ensures that only the currently executing instruction is visible i…☆66Apr 2, 2025Updated last year
- Evasion kit for Cobalt Strike☆31Jan 16, 2026Updated 6 months ago
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆26May 10, 2026Updated 2 months ago
- SafeHarbor revamped with Direct Syscalls using InlineWhispers3☆15Feb 16, 2026Updated 5 months ago
- ☆73Dec 19, 2024Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- out-of-tree LLVM 21+ pass plugin for policy-driven IR obfuscation.☆91Jul 12, 2026Updated last week
- Atomic test units for BOF execution☆60Apr 26, 2026Updated 3 months ago
- Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.☆85Jun 15, 2026Updated last month
- ☆86Feb 12, 2026Updated 5 months ago
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 2 months ago
- Tailscale/Headscale C2 profile and agent for Mythic☆25Mar 14, 2026Updated 4 months ago
- Implementing Ghostly-Hollowing using tampered syscalls for remote PE injection☆75Dec 26, 2025Updated 6 months ago
- ☆71Apr 20, 2026Updated 3 months ago
- A PoC UDRL for Cobalt Strike built with Crystal Palace that combines Raphael Mudge's page streaming technique with a modular call gate (D…☆135Jan 21, 2026Updated 6 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.☆103Jun 24, 2026Updated last month
- ☆200Jun 11, 2026Updated last month
- Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijac…☆129Updated this week
- RunPE implementation with multiple evasive techniques (2)☆283Sep 25, 2025Updated 10 months ago
- .NET CLR-Stomping☆146May 20, 2026Updated 2 months ago
- Self-cleaning in-memory PICO loader for Crystal Palace. Automatically erases traces and operates entirely in memory for stealthy payload …☆57Nov 2, 2025Updated 8 months ago
- A POC tool for exploring dev-tunnels☆66May 5, 2026Updated 2 months ago