load arbitrary dlls, call any exported function, calls execute inside g0 as normal syscalls do from the traditional route, no syscall or windows imports, exposes many convenience functions for winapi interaction :3
☆31May 4, 2026Updated 3 months ago
Alternatives and similar repositories for go-wincall
Users that are interested in go-wincall are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- low-level windows networking library using afd.sys sockets and schannel tls. bypasses winsock, winhttp, wininet and other high-level netw…☆17Jul 15, 2026Updated last month
- A cryptographic payload loader and executor designed for advanced in-memory execution techniques. This project combines strong encryption…☆30Mar 2, 2026Updated 5 months ago
- go-native-syscall is Go (+ asm) Windows syscall library that resolves, hashes, caches, and invokes direct (and indirect now) NT calls wit…☆18Aug 13, 2025Updated last year
- Anti-Debugging (Self-Debugging)☆17Sep 6, 2025Updated 11 months ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 4 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Windows Application Attack Surface Analyzer☆27Feb 22, 2024Updated 2 years ago
- ☆52Jun 12, 2026Updated 2 months ago
- Simple KDMapper driver dumper. Unlike other dumpers, this dumper dumps the PE headers of the image too.☆18May 10, 2024Updated 2 years ago
- DPAPI research and offensive tools☆17Feb 12, 2026Updated 6 months ago
- Implementation of KlezVirus' silent moonwalk approach for payloads☆18Feb 13, 2026Updated 6 months ago
- Fork of pkg/debug that adds some additional functionality.☆130Feb 14, 2026Updated 6 months ago
- ShadowStrike A Windows EDR Platform☆36Updated this week
- Async BOF that monitors USB device connect/disconnect events, reports device information and performs actions on connected USB storage vo…☆58Jul 23, 2026Updated last month
- Async port/ping scanner BOF. Supports IP/port ranges, CIDR notation and hostnames.☆17Jul 23, 2026Updated last month
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- COM Windows Persistence Technique☆90Apr 27, 2026Updated 4 months ago
- A tool for exploiting Kerberos tickets against system with Credential Guard enabled.☆20Sep 2, 2025Updated 11 months ago
- Run native PE or .NET executables entirely in-memory. Build the loader as an .exe or .dll—DllMain is Cobalt Strike UDRL-compatible☆276Jun 18, 2025Updated last year
- BadExclusions is a tool to identify folder custom or undocumented exclusions on AV/EDR☆21Feb 8, 2024Updated 2 years ago
- Process Hollowing in Rust with Process Executable Relocation Support for both 32 and 64 bit architecture environments.☆26Jan 6, 2025Updated last year
- StoneKeeper C2, an experimental EDR evasion framework for research purposes☆209Dec 25, 2024Updated last year
- Shellcode capable of bypassing EAF / IAF mitigations☆30Apr 11, 2023Updated 3 years ago
- Reversed WintaPix Malware Source code | That targets countries in the Middle East and abuse KeServiceDescriptorTable(SSDT), persistence a…☆21Jul 6, 2024Updated 2 years ago
- MacOS Shared Library to Shellcode Loader☆90Feb 23, 2026Updated 6 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- A credential extraction BOF for Veeam Backup and Replication and Veeam One☆80Jul 1, 2026Updated last month
- A portable bridge between your C2 infrastructure and Discord, built for quick and lightweight operations.☆13Jun 3, 2025Updated last year
- Print the stack trace☆51Mar 8, 2026Updated 5 months ago
- first public in-process reflective PE loader for .NET NativeAOT binaries. maps a NativeAOT executable into the current process and execut…☆29Mar 28, 2026Updated 5 months ago
- Async BOF to automatically extract or renew Kerberos TGTs on a target system.☆135Jul 23, 2026Updated last month
- Azure Blob Storage C2 Profile for Mythic☆30Jan 30, 2026Updated 7 months ago
- Fully documented, updated, and comprehensive utilities for Windows 32-bit Wow64 processes☆18Aug 15, 2025Updated last year
- Havoc C2 BOF port of the KslD.sys BYOVD technique. Credential extraction from lsass via physical memory — no OpenProcess, no auditable AP…☆147Apr 22, 2026Updated 4 months ago
- A small set of Beacon Object Files (BOFs) that I developed over the time with a Magic: The Gathering theme.☆21Jul 15, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Short Programs For Spreading Malware☆16Aug 11, 2021Updated 5 years ago
- Templates for developing your own listeners and agents for AdaptixC2.☆58Feb 28, 2026Updated 6 months ago
- Beacon Object File (BOF) for identifying dependent child services of a given parent.☆19Jun 20, 2025Updated last year
- Advanced OPSEC fork of Donut. Features a Custom in-memory CLR Host, Tail-Jump ETW bypasses, and zero-patch AMSI evasion for stealthy shel…☆72Jun 24, 2026Updated 2 months ago
- PoC on JIT Flow Redirection and .NET Reflection for Analyzing In-Memory Telemetry Interfaces (AMSI/ETW)☆17Jun 24, 2026Updated 2 months ago
- Opengraph-Compatible JSON Generator for BloodHound☆28Mar 30, 2026Updated 5 months ago
- From 2011: Quickly search for files in NTFS volumes parsing the Master File Table (MFT). A decent amount of how NTFS and MFT work was pai…☆28Oct 14, 2019Updated 6 years ago