Bypassing AVs and Sandboxes
☆21Oct 9, 2025Updated 9 months ago
Alternatives and similar repositories for BypassingAVs
Users that are interested in BypassingAVs are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆36Jul 1, 2025Updated last year
- ShadowDropper is a utility for covertly delivering and executing payloads on a target system.☆27Jul 4, 2025Updated last year
- A professional Red Team / Pentest tool for assessing the external perimeter of a company in a complete "black box" mode (zero knowledge, …☆29Feb 15, 2026Updated 5 months ago
- A C# PE loader for x64 and x86 PE files.☆56Mar 9, 2026Updated 4 months ago
- 免杀木马样本☆107Oct 11, 2025Updated 9 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- PowerShell module for mapping byte offsets to source context and locating AMSI or Microsoft Defender detection boundaries in text and bin…☆35Jul 13, 2026Updated last week
- **CVE-2026-2636** is a vulnerability in the Windows Common Log File System (CLFS) driver (`CLFS.sys`). An unprivileged user can trigger a…☆15Feb 26, 2026Updated 4 months ago
- open source port/reimplementation of the Cobalt Strike BOF Loader as is☆73Mar 8, 2026Updated 4 months ago
- A BOF that's a BOF Loader and more☆209Apr 6, 2026Updated 3 months ago
- EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies☆44Jun 8, 2026Updated last month
- Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification s…☆40Jun 4, 2026Updated last month
- Zero dependency browser extension for handling import of cookies, Microsoft 365 OAuth tokens, and Graph API interactions.☆35Jun 5, 2026Updated last month
- This tool helps inject code into the processes of Antivirus programs.☆189May 23, 2026Updated last month
- Evasive loader for .NET Framework assemblies☆44May 14, 2026Updated 2 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Evade behavioral analysis by executing malicious code within trusted Microsoft call stacks, patchless hooking library IAT/EAT.☆146Dec 8, 2025Updated 7 months ago
- A guide to modern exploit development, shellcode, EDR and WAF bypass, and initial Red Team access.☆31Mar 6, 2026Updated 4 months ago
- PhantomStego — Ultimate Steganography Tool☆28Nov 17, 2025Updated 8 months ago
- Tools for generating and validating IBANs (International Bank Account Numbers)☆10Aug 11, 2020Updated 5 years ago
- PPLReaper is a Windows UNSIGNED kernel driver + userland companion tool designed to inspect and manipulate Protected Process Light (PPL) …☆24Mar 4, 2026Updated 4 months ago
- shellcode transformation tool for YARA evasion☆62Dec 17, 2025Updated 7 months ago
- Windows Access token manipulation tool made in C#☆25Aug 24, 2025Updated 10 months ago
- BYOVD hunter to help prioritize windows drivers worth manual analysis☆131Aug 19, 2025Updated 11 months ago
- RProxy LAB is intended solely for educational purposes and authorized security testing with EvilGinx / Modlishka / EvilPuppet e.t.c tools☆66Updated this week
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- open source implementation of the UDC2 spec used in Cobalt Strike☆55Jul 4, 2026Updated 2 weeks ago
- Fairy Law - Compromise or disable EDR security solutions☆79Dec 1, 2025Updated 7 months ago
- NCrypt portable crypter is a collection of C++ build tools, a tiny C compiler for the stub, and a useful codebase for anyone wanting to c…☆19Mar 14, 2024Updated 2 years ago
- PE Sections Packer + Loader for Windows - Packs a DLL/EXE file and maps it into the loader (C/C++)☆15Oct 19, 2025Updated 9 months ago
- DRILL (Distributable Remote Integrated Lightweight Link) is a powerful and stealthy Command and Control (C2) framework designed for seaml…☆38Jul 31, 2025Updated 11 months ago
- A Proof of Concept demonstrating CET-compliant callstack spoofing in Rust. It leverages Windows Thread Pool and Enum Callback trampolinin…☆45Jul 12, 2026Updated last week
- Locate dlls and function addresses without PEB Walk and EAT parsing☆110Nov 7, 2025Updated 8 months ago
- KittyLoader is a highly evasive loader written in C / Assembly☆267Sep 22, 2025Updated 9 months ago
- Spoof parent process ID☆14Jan 23, 2019Updated 7 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Lab research on Windows loader internals, PE loading, stack artifacts, and execution tradeoffs.☆237May 4, 2026Updated 2 months ago
- ☆199Jun 11, 2026Updated last month
- Windows C++ Implant for Exploration C2☆49May 11, 2026Updated 2 months ago
- Cobalt Strike BOF for beacon/shellcode injection using fork & run technique with Draugr synthetic stack frames☆156Nov 23, 2025Updated 7 months ago
- Obex – Blocking unwanted DLLs in user mode☆279Sep 18, 2025Updated 10 months ago
- The code I write in my blog☆115Jun 27, 2026Updated 3 weeks ago
- ☆50Dec 5, 2025Updated 7 months ago