Clean Indirect Syscalls with Hook Evasion & Return Address Spoofing.
☆100Apr 30, 2026Updated 3 months ago
Alternatives and similar repositories for DoomSyscalls
Users that are interested in DoomSyscalls are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- BingusLdr is a DLL loader built with Crystal Palace that uses a CET compatible stack spoofing technique.☆112Jul 14, 2026Updated last month
- Locate dlls and function addresses without PEB Walk and EAT parsing☆109Nov 7, 2025Updated 9 months ago
- BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation☆135Mar 27, 2026Updated 4 months ago
- A EDR bypassing shellcode loader framework for Windows 10 64bit, featuring ETW/AMSI patching, Tartarus Gate, process protection and more☆94Jun 24, 2026Updated last month
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆27May 21, 2026Updated 2 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Polymorphic PE rewriter for Windows x64 , rewrites binaries into semantically identical but byte-different variants☆200Jun 6, 2026Updated 2 months ago
- ☆88Apr 8, 2026Updated 4 months ago
- A collection of DPAPI hunting and parsing BOFs☆38Mar 3, 2026Updated 5 months ago
- Evade behavioral analysis by executing malicious code within trusted Microsoft call stacks, patchless hooking library IAT/EAT.☆149Dec 8, 2025Updated 8 months ago
- Evasive loader for .NET Framework assemblies☆83May 12, 2026Updated 3 months ago
- COM Windows Persistence Technique☆90Apr 27, 2026Updated 3 months ago
- ☆60Jul 12, 2026Updated last month
- Technical Reference to multiple relay techniques☆193May 21, 2026Updated 2 months ago
- ☆23May 19, 2026Updated 2 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Sleep replacement that executes real, varied work to break behavioral pattern matching by EDR and anti-cheat systems☆34Jul 20, 2026Updated 3 weeks ago
- Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin res…☆88Jun 20, 2026Updated last month
- A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Slee…☆80Jul 26, 2026Updated 2 weeks ago
- A Crystal Palace shared library to resolve & perform syscalls☆66Oct 29, 2025Updated 9 months ago
- Using Just In Time (JIT) instruction decryption, this shellcode loader ensures that only the currently executing instruction is visible i…☆67Apr 2, 2025Updated last year
- Evasion kit for Cobalt Strike☆31Jan 16, 2026Updated 6 months ago
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆27May 10, 2026Updated 3 months ago
- SafeHarbor revamped with Direct Syscalls using InlineWhispers3☆15Feb 16, 2026Updated 5 months ago
- ☆75Dec 19, 2024Updated last year
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- out-of-tree LLVM 21+ pass plugin for policy-driven IR obfuscation.☆97Updated this week
- Atomic test units for BOF execution☆60Apr 26, 2026Updated 3 months ago
- Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.☆87Jun 15, 2026Updated last month
- ☆86Feb 12, 2026Updated 6 months ago
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 3 months ago
- Tailscale/Headscale C2 profile and agent for Mythic☆25Mar 14, 2026Updated 5 months ago
- Implementing Ghostly-Hollowing using tampered syscalls for remote PE injection☆75Dec 26, 2025Updated 7 months ago
- ☆72Apr 20, 2026Updated 3 months ago
- A PoC UDRL for Cobalt Strike built with Crystal Palace that combines Raphael Mudge's page streaming technique with a modular call gate (D…☆138Jan 21, 2026Updated 6 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.☆125Jun 24, 2026Updated last month
- ☆213Jun 11, 2026Updated 2 months ago
- Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijac…☆155Jul 20, 2026Updated 3 weeks ago
- .NET CLR-Stomping☆148May 20, 2026Updated 2 months ago
- RunPE implementation with multiple evasive techniques (2)☆286Sep 25, 2025Updated 10 months ago
- Self-cleaning in-memory PICO loader for Crystal Palace. Automatically erases traces and operates entirely in memory for stealthy payload …☆57Nov 2, 2025Updated 9 months ago
- A POC tool for exploring dev-tunnels☆66May 5, 2026Updated 3 months ago