The samples referenced in my book, Evasive Malware (No starch Press)
☆62Feb 20, 2026Updated 5 months ago
Alternatives and similar repositories for Evasive_Malware_Book_Samples
Users that are interested in Evasive_Malware_Book_Samples are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago
- A PoC Cobalt Strike UDRL written in Rust☆32Jun 20, 2026Updated last month
- Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable…☆33Mar 28, 2026Updated 3 months ago
- IoT Firmware Deep Analysis: Automated reverse engineering and vulnerability discovery for IoT firmware binaries.☆23Jul 9, 2026Updated last week
- open source implementation of the UDC2 spec used in Cobalt Strike☆55Jul 4, 2026Updated 2 weeks ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification s…☆40Jun 4, 2026Updated last month
- ☆50Dec 5, 2025Updated 7 months ago
- Remote DLL Injection with Timer-based Shellcode Execution☆216Jul 18, 2025Updated last year
- ☆199Jun 11, 2026Updated last month
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆273Apr 16, 2026Updated 3 months ago
- ☆51Jul 12, 2026Updated last week
- BYOVD hunter to help prioritize windows drivers worth manual analysis☆131Aug 19, 2025Updated 11 months ago
- Object file loader implemented as a post-ex DLL for asynchronous BOF execution.☆29Jun 15, 2026Updated last month
- This repository contains the research tool presented at x33fcon 2026, along with the associated presentation slides. The content is made …☆62Jun 15, 2026Updated last month
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Hijacks code execution via overwriting Control Flow Guard pointers in combase.dll☆155Apr 18, 2025Updated last year
- BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation☆132Mar 27, 2026Updated 3 months ago
- A tool to easily perform GitLab Device Code Phishing on red team engagements☆51Feb 9, 2026Updated 5 months ago
- Creation of multiple Malware tools consisting of evasion, enumeration and exploitation☆102May 29, 2026Updated last month
- modified mssqlclient from impacket to extract policies from the SCCM database☆47Feb 24, 2026Updated 4 months ago
- Generate and Manage KeyCredentialLinks☆257Updated this week
- A Windows rootkit that turns user-land processes into Protected Processes☆30Nov 16, 2024Updated last year
- Combining KslDump and GhostKatz to dump LSASS using no-fix KslD.sys memory read to bypass PPL. Extracts MSV1_0 NT hashes and WDigest clea…☆45Mar 27, 2026Updated 3 months ago
- Async BOF that monitors USB device connect/disconnect events, reports device information and performs actions on connected USB storage vo…☆56Jun 17, 2026Updated last month
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass☆144Jan 29, 2026Updated 5 months ago
- ☆16Apr 29, 2026Updated 2 months ago
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆46Jun 18, 2026Updated last month
- Active Directory forensic framework☆16May 18, 2026Updated 2 months ago
- A synergized Visual Studio and Rust development environment☆19Jan 25, 2025Updated last year
- Print the stack trace☆51Mar 8, 2026Updated 4 months ago
- Polymorphic AV/AMSI bypass toolkit - Donut shellcode runner for offensive .NET/PE tools☆36May 26, 2026Updated last month
- Atomic test units for BOF execution☆60Apr 26, 2026Updated 2 months ago
- Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods…☆191Apr 27, 2026Updated 2 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Bof of RegPwn by MDSec☆127Mar 15, 2026Updated 4 months ago
- Crystal Palace Evasion kit for Sliver☆97Jun 13, 2026Updated last month
- BOF for extracting Edge credentials from the main browser process.☆49May 5, 2026Updated 2 months ago
- A simple C2 Framework written in modern C++☆31Jul 2, 2026Updated 2 weeks ago
- Phantom is project created to perform loading and executing unmanaged code in memory within an IIS environment running in full‑trust mode…☆107Jun 5, 2026Updated last month
- Modules designed to be used with the Conquest framework.☆22Jun 11, 2026Updated last month
- windows api bug☆39May 24, 2026Updated last month