ariary / fileless-xecLinks
Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)
☆204Updated last year
Alternatives and similar repositories for fileless-xec
Users that are interested in fileless-xec are comparing it to the libraries listed below
Sorting:
- Golang binary for data exfiltration with ICMP protocol (+ ICMP bindshell, http over ICMP tunneling, ...)☆166Updated 4 years ago
- WIP shellcode loader in nim with EDR evasion techniques☆221Updated 3 years ago
- KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this p…☆228Updated 2 years ago
- eXtensiable Malware Toolkit: Full Featured Golang C2 Framework with Awesome Features☆102Updated last week
- A C2 framework for initial access in Go☆196Updated 3 years ago
- Post-exploitation agent for Merlin☆202Updated 8 months ago
- A BOF to automate common persistence tasks for red teamers☆291Updated 2 years ago
- A technique of hiding malicious shellcode via Shannon encoding.☆260Updated 3 years ago
- Extendable payload obfuscation and delivery framework☆145Updated 3 years ago
- indirect syscalls for AV/EDR evasion in Go assembly☆345Updated 2 years ago
- grim reaper c2☆345Updated 3 years ago
- A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!☆337Updated last year
- The Official Sliver Armory☆124Updated 8 months ago
- A Nim implementation of reflective PE-Loading from memory☆296Updated last year
- (Demo) 3rd party agent for Havoc☆147Updated 2 years ago
- Get fresh Syscalls from a fresh ntdll.dll copy☆236Updated 3 years ago
- A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.☆301Updated 3 years ago
- Go shellcode loader that combines multiple evasion techniques☆387Updated 2 years ago
- ☆246Updated 3 years ago
- ☆170Updated 4 years ago
- Process Ghosting Tool☆174Updated 4 years ago
- WMEye is a post exploitation tool that uses WMI Event Filter and MSBuild Execution for lateral movement☆370Updated 4 years ago
- Cobalt Strike BOF - Bypass AMSI in a remote process with code injection.☆382Updated 2 years ago
- 🔎🪲 Malleable C2 profiles parser and assembler written in golang☆65Updated last year
- Pass the Hash to a named pipe for token Impersonation☆312Updated 2 years ago
- Python implementation for PrintNightmare (CVE-2021-1675 / CVE-2021-34527)☆202Updated 4 years ago
- This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python withou…☆187Updated 4 months ago
- Convert shellcode into different formats!☆360Updated 2 years ago
- This is a PoC for bypassing UAC using DLL hijacking and abusing the "Trusted Directories" verification.☆278Updated 4 years ago
- Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.☆126Updated 2 years ago