Rootkit for the blue team. Sophisticated and optimized LKM to detect and prevent malicious activity
☆34Apr 26, 2024Updated 2 years ago
Alternatives and similar repositories for GoodKit
Users that are interested in GoodKit are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- UFSIT scripts and tools for hardening and auditing☆14May 28, 2025Updated last year
- Threadless shellcode injection tool☆68Aug 5, 2024Updated 2 years ago
- AI-based implant feature☆25Apr 28, 2025Updated last year
- Top hashpwn rules☆21Dec 12, 2025Updated 7 months ago
- A Rust version of Mirage, a PoC memory evasion technique that relies on a vulnerable VBS enclave to hide shellcode within VTL1.☆40Mar 6, 2025Updated last year
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- GhostWriting Injection Technique.☆199Mar 26, 2018Updated 8 years ago
- A different approach to writing BOFs in rust.☆21Aug 20, 2025Updated 11 months ago
- A collection of commands, tools, techniques and procedures of the purplestorm ctf team.☆14Mar 20, 2025Updated last year
- Indirect syscalls + DInvoke made simple.☆95Dec 24, 2024Updated last year
- kubernetes rootkit☆35Dec 18, 2023Updated 2 years ago
- A powerful Windows UI monitoring and DNS exfiltration tool written in Rust, combining advanced UI event capture capabilities with secure …☆20Mar 6, 2025Updated last year
- Sample Rust Hooking Engine☆34Apr 5, 2024Updated 2 years ago
- StealthGuardian is a middleware layer that can be combined with adversary simulation tools to verify the resistance, detection level and…☆20Aug 7, 2024Updated 2 years ago
- ☆15Jan 15, 2026Updated 6 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A remote unauthenticated DOS POC exploit that targets the authentication implementation of Havoc.☆36Nov 16, 2023Updated 2 years ago
- early cascade injection PoC based on Outflanks blog post, in rust☆64Nov 8, 2024Updated last year
- Rust implementation of phantom persistence technique documented in https://blog.phantomsec.tools/phantom-persistence☆65Jun 23, 2025Updated last year
- ☆107Jan 21, 2025Updated last year
- A COFF Loader written in Rust☆146Dec 1, 2025Updated 8 months ago
- Heap encryption in Nim☆21Aug 25, 2024Updated last year
- PEIM (UEFI) bootkit targeting OVMF (EDK2)☆40Nov 28, 2023Updated 2 years ago
- Vulnerable kernel drivers to kill EDR☆18Aug 11, 2025Updated last year
- Simple reverse ICMP shell☆14Apr 30, 2024Updated 2 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- A modern Rust implementation of the original Stardust project, providing a sophisticated 32/64-bit shellcode template that features posit…☆65Mar 17, 2025Updated last year
- A Rust port of LayeredSyscall — performs indirect syscalls while generating legitimate API call stack frames by abusing VEH.☆166Oct 31, 2024Updated last year
- Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar☆139Aug 10, 2024Updated 2 years ago
- Sleep obfuscation for shellcode implants and their reflective shit☆55Sep 19, 2023Updated 2 years ago
- Mythic C2 wrapper for NimSyscallPacker☆26Mar 12, 2025Updated last year
- powershell script i wrote that can suspend an arbitrary process (with limits)☆22Mar 26, 2023Updated 3 years ago
- Evasive shellcode loader for Red Teaming☆18Aug 15, 2025Updated 11 months ago
- Cobalt Strike UDRL for memory scanner evasion.☆52Dec 4, 2023Updated 2 years ago
- Remote Thread Detection with a Kernel Driver☆35Jan 14, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A nim implementation of sRDI☆20Oct 18, 2023Updated 2 years ago
- Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry☆479Aug 2, 2024Updated 2 years ago
- Tools for analyzing EDR agents☆279Jun 10, 2024Updated 2 years ago
- winPEAS, but for Active Directory☆179Apr 1, 2025Updated last year
- Automated .NET AppDomain hijack payload generation☆129Feb 4, 2025Updated last year
- A tool to assist DLL hijacking via the Havoc GUI☆14Jan 9, 2024Updated 2 years ago
- CSharp reimplementation of Venoma, another C++ Cobalt Strike beacon dropper with custom indirect syscalls execution☆51Apr 22, 2024Updated 2 years ago