Simple Windows shellcode loader with interesting evasion tricks
☆15Apr 27, 2025Updated last year
Alternatives and similar repositories for hell-code-loader
Users that are interested in hell-code-loader are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A large collection of blogs 🦐☆13Apr 12, 2025Updated last year
- PoC for AMD Ryzen driver.☆20Jan 12, 2026Updated 6 months ago
- A Bof to dump domain credentials via DRSGetNCChanges, Created for use with the Adaptix C2.☆15Dec 16, 2025Updated 7 months ago
- Official public advisory for CVE-2025-61155☆26Feb 9, 2026Updated 5 months ago
- Local Privilege Escalation Affecting Millions of Gaming Laptops☆61Jan 19, 2026Updated 6 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- NTAPI hook bypass with (semi) legit stack trace☆18May 9, 2023Updated 3 years ago
- TheDarkMark is a C2 framework designed to be fast and parallel.☆23Dec 2, 2025Updated 7 months ago
- Windows memory scanner for call stack spoofing detection, unbacked shellcode, injected DLLs and in-memory C2 implants.☆37May 22, 2026Updated last month
- NASM/GoLink OpenGL 1k Framework☆13Dec 25, 2017Updated 8 years ago
- Shared Memory Driver for EAC (Specifically for RUST, Tested)☆31Apr 23, 2026Updated 2 months ago
- A small set of Beacon Object Files (BOFs) that I developed over the time with a Magic: The Gathering theme.☆21Jul 15, 2025Updated last year
- Beacon Object File (BOF) to retrieve and decrypt the the LAPSv2 password from the Windows Active Directory and Microsoft Azure/Entra Acti…☆20Oct 24, 2025Updated 8 months ago
- CVE-2025-7771: Arbitrary physical memory and I/O port read/write via ThrottleStop driver☆18Sep 5, 2025Updated 10 months ago
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.☆56Mar 30, 2026Updated 3 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Repository hosting a hypothetical EDR Spoofer, as discovered originally by Nightmare-Eclipse☆41May 27, 2026Updated last month
- PolyEngine is an evasive PE packer designed for CTF challenges and low-level Windows security education. It focuses on bypassing EDR and …☆148Jun 10, 2026Updated last month
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆46Jun 18, 2026Updated last month
- C++ tool and library for converting .bin files to shellcode in multiple output formats.☆33Aug 18, 2025Updated 11 months ago
- Crystal Palace library for proxying Nt API calls via the Threadpool☆105Oct 18, 2025Updated 9 months ago
- Terminate AV/EDR processes by exploiting the vulnerable NsecSoft driver☆32Sep 15, 2025Updated 10 months ago
- Alternative Read and Write primitives using Rtl* functions the unintended way.☆79Aug 25, 2025Updated 10 months ago
- ☆16Oct 31, 2021Updated 4 years ago
- Loader Pre-Technology, Main thread hijacking without using API, get ntdll and kernel32 handle without peb. 加载器前置技术,不使用API进行主线程劫持,不使用PEB…☆93Jul 26, 2025Updated 11 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- A manual PE mapping implementation, aka reflective loader☆23Feb 28, 2026Updated 4 months ago
- ScyllaHide custom version for ida9.x☆20Sep 5, 2025Updated 10 months ago
- A C++ library to parse and write Java Bytecode☆19Dec 17, 2025Updated 7 months ago
- An NTP channel for Beacons, implemented using Cobalt Strike’s External C2 framework.☆35Oct 6, 2025Updated 9 months ago
- Shellcode capable of bypassing EAF / IAF mitigations☆30Apr 11, 2023Updated 3 years ago
- Java class patcher using ASM and compatible with Minecraft Forge☆11Oct 3, 2021Updated 4 years ago
- A tool to easily perform GitLab Device Code Phishing on red team engagements☆51Feb 9, 2026Updated 5 months ago
- A tool designed to hook into Windows applications and output named (and anonymous?) pipe traffic.☆17Feb 27, 2024Updated 2 years ago
- Async BOF Framework - Real-time event monitoring for Cobalt Strike Beacon☆30May 18, 2026Updated 2 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- PE Sections Packer + Loader for Windows - Packs a DLL/EXE file and maps it into the loader (C/C++)☆15Oct 19, 2025Updated 9 months ago
- a header-only library to dynamically resolve modules and exports while also being able to call them directly☆24Dec 20, 2023Updated 2 years ago
- Here you can find some vulnerable Windows Kernel Drivers☆13Feb 21, 2025Updated last year
- Hidden RDP☆24Sep 20, 2024Updated last year
- Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials☆61May 12, 2025Updated last year
- Beacon Object File (BOF) for Using the BadSuccessor Technique for Account Takeover