Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.
☆67Mar 2, 2026Updated 5 months ago
Alternatives and similar repositories for zig-pe
Users that are interested in zig-pe are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆18Dec 11, 2025Updated 8 months ago
- A EDR bypassing shellcode loader framework for Windows 10 64bit, featuring ETW/AMSI patching, Tartarus Gate, process protection and more☆94Jun 24, 2026Updated last month
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago
- ☆60Jul 12, 2026Updated last month
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 3 months ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Create local administrators with the SAMR API (lowest-level technique). Implemented in C#, Crystal, Python and Rust☆95Mar 7, 2026Updated 5 months ago
- From C, Rust or Zig to binary shellcode compiler based on Mingw gcc. It allows using Win32 APIs and standard libraries without any change…☆56Mar 16, 2026Updated 4 months ago
- Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable…☆33Mar 28, 2026Updated 4 months ago
- Stealthy .NET assembly loading using AssemblyNative::LoadFromBuffer☆58Mar 22, 2026Updated 4 months ago
- Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. Implemented in C#, C++, Crystal, P…☆154Feb 17, 2026Updated 5 months ago
- open source implementation of the UDC2 spec used in Cobalt Strike☆58Jul 4, 2026Updated last month
- Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.☆66May 4, 2026Updated 3 months ago
- An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard histor…☆114Apr 16, 2026Updated 3 months ago
- A Windows tool that converts LDIF files to BloodHound CE☆31Dec 20, 2025Updated 7 months ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆27May 21, 2026Updated 2 months ago
- Object file loader implemented as a post-ex DLL for asynchronous BOF execution.☆29Jul 23, 2026Updated 2 weeks ago
- Automated script for obfuscating, rebranding and renaming the Havoc C2 Framework to evade AV/EDR and C2 hunters.☆49Aug 13, 2025Updated 11 months ago
- load shellcode without P/D Invoke and VirtualProtect call.☆172Sep 2, 2025Updated 11 months ago
- Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.☆42Aug 5, 2025Updated last year
- COM Windows Persistence Technique☆90Apr 27, 2026Updated 3 months ago
- Phantom is project created to perform loading and executing unmanaged code in memory within an IIS environment running in full‑trust mode…☆108Jun 5, 2026Updated 2 months ago
- A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Slee…☆78Jul 26, 2026Updated 2 weeks ago
- UDC2 implementation that provides an ICMP C2 channel☆126Nov 24, 2025Updated 8 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Morpheus is an lsass stealer that extracts lsass.exe in RAM and exfiltrates it via forged and crypted NTP packets. For authorized testin…☆168Jun 19, 2025Updated last year
- A stealthier approach to WMI-based command execution using Impacket without touching the disk.☆87Mar 15, 2026Updated 4 months ago
- A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge …☆34Mar 20, 2023Updated 3 years ago
- Automatically deploying Mythic C2 in Azure using Terraform☆25Jul 3, 2026Updated last month
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆277Apr 16, 2026Updated 3 months ago
- Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijac…☆156Jul 20, 2026Updated 3 weeks ago
- DynLoader A modular Windows loader focused on EDR evasion Built with indirect syscall (Tartarus Gate / Hell’s Gate), Manual PE parsing …☆81Jul 10, 2026Updated last month
- Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. Implemented in C#…☆372Feb 2, 2026Updated 6 months ago
- ☆86Feb 12, 2026Updated 5 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Havoc C2 BOF port of the KslD.sys BYOVD technique. Credential extraction from lsass via physical memory — no OpenProcess, no auditable AP…☆145Apr 22, 2026Updated 3 months ago
- Async port/ping scanner BOF. Supports IP/port ranges, CIDR notation and hostnames.☆18Jul 23, 2026Updated 2 weeks ago
- Lateral movement with DCOM DLL hijacking☆182Jul 4, 2025Updated last year
- AppLocker-Based EDR Neutralization☆340Dec 19, 2025Updated 7 months ago
- Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass☆144Jan 29, 2026Updated 6 months ago
- NØW is a word-based shellcode encoding and obfuscation tool that transforms raw shellcode bytes into natural-looking English prose.☆75Jun 24, 2026Updated last month
- Arsenal of modules to beacon postex☆107Mar 13, 2026Updated 4 months ago