Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.
☆67Mar 2, 2026Updated 4 months ago
Alternatives and similar repositories for zig-pe
Users that are interested in zig-pe are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆18Dec 11, 2025Updated 7 months ago
- A EDR bypassing shellcode loader framework for Windows 10 64bit, featuring ETW/AMSI patching, Tartarus Gate, process protection and more☆78Jun 24, 2026Updated 3 weeks ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago
- ☆52Jul 12, 2026Updated last week
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 2 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Create local administrators with the SAMR API (lowest-level technique). Implemented in C#, Crystal, Python and Rust☆93Mar 7, 2026Updated 4 months ago
- Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable…☆33Mar 28, 2026Updated 3 months ago
- From C, Rust or Zig to binary shellcode compiler based on Mingw gcc. It allows using Win32 APIs and standard libraries without any change…☆56Mar 16, 2026Updated 4 months ago
- Stealthy .NET assembly loading using AssemblyNative::LoadFromBuffer☆58Mar 22, 2026Updated 4 months ago
- Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. Implemented in C#, C++, Crystal, P…☆153Feb 17, 2026Updated 5 months ago
- open source implementation of the UDC2 spec used in Cobalt Strike☆55Jul 4, 2026Updated 2 weeks ago
- Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.☆66May 4, 2026Updated 2 months ago
- An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard histor…☆114Apr 16, 2026Updated 3 months ago
- A Windows tool that converts LDIF files to BloodHound CE☆31Dec 20, 2025Updated 7 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆27May 21, 2026Updated 2 months ago
- Object file loader implemented as a post-ex DLL for asynchronous BOF execution.☆29Jun 15, 2026Updated last month
- Automated script for obfuscating, rebranding and renaming the Havoc C2 Framework to evade AV/EDR and C2 hunters.☆49Aug 13, 2025Updated 11 months ago
- load shellcode without P/D Invoke and VirtualProtect call.☆172Sep 2, 2025Updated 10 months ago
- Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.☆42Aug 5, 2025Updated 11 months ago
- Phantom is project created to perform loading and executing unmanaged code in memory within an IIS environment running in full‑trust mode…☆107Jun 5, 2026Updated last month
- COM Windows Persistence Technique☆89Apr 27, 2026Updated 2 months ago
- A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Slee…☆70Jul 11, 2026Updated last week
- UDC2 implementation that provides an ICMP C2 channel☆125Nov 24, 2025Updated 7 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Morpheus is an lsass stealer that extracts lsass.exe in RAM and exfiltrates it via forged and crypted NTP packets. For authorized testin…☆168Jun 19, 2025Updated last year
- A stealthier approach to WMI-based command execution using Impacket without touching the disk.☆86Mar 15, 2026Updated 4 months ago
- A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge …☆32Mar 20, 2023Updated 3 years ago
- Automatically deploying Mythic C2 in Azure using Terraform☆22Jul 3, 2026Updated 2 weeks ago
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆273Apr 16, 2026Updated 3 months ago
- Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijac…☆126Updated this week
- Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. Implemented in C#…☆372Feb 2, 2026Updated 5 months ago
- DynLoader A modular Windows loader focused on EDR evasion Built with indirect syscall (Tartarus Gate / Hell’s Gate), Manual PE parsing …☆76Jul 10, 2026Updated last week
- ☆85Feb 12, 2026Updated 5 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Havoc C2 BOF port of the KslD.sys BYOVD technique. Credential extraction from lsass via physical memory — no OpenProcess, no auditable AP…☆144Apr 22, 2026Updated 3 months ago
- Async port/ping scanner BOF. Supports IP/port ranges, CIDR notation and hostnames.☆18Updated this week
- Lateral movement with DCOM DLL hijacking☆182Jul 4, 2025Updated last year
- AppLocker-Based EDR Neutralization☆339Dec 19, 2025Updated 7 months ago
- Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass☆144Jan 29, 2026Updated 5 months ago
- Arsenal of modules to beacon postex☆105Mar 13, 2026Updated 4 months ago
- NØW is a word-based shellcode encoding and obfuscation tool that transforms raw shellcode bytes into natural-looking English prose.☆74Jun 24, 2026Updated 3 weeks ago