Detonate redteam tools on VMs and get logs & detection status
☆97Jun 22, 2026Updated 3 weeks ago
Alternatives and similar repositories for DetonatorAgent
Users that are interested in DetonatorAgent are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Deep insights into EDR detection approaches☆24Jul 7, 2026Updated last week
- Open Source Implementation of Cobalt Strike's Malleable C2☆104Jun 27, 2026Updated 3 weeks ago
- Orchestrate detonating redteam artifacts in VMs with different EDRs to see their detection surface.☆63Jun 24, 2026Updated 3 weeks ago
- some research on EDR deconditioning☆15Jun 4, 2026Updated last month
- The dragon in the dark. A red team post exploitation framework for testing security controls during red team assessments.☆507Mar 15, 2026Updated 4 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Windows C/C++ development environment on Linux☆18Mar 29, 2026Updated 3 months ago
- Awesome MalDev Links☆77Jun 21, 2026Updated 3 weeks ago
- Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !☆43Mar 24, 2026Updated 3 months ago
- open source port/reimplementation of the Cobalt Strike BOF Loader as is☆73Mar 8, 2026Updated 4 months ago
- This is practice VM for malware development☆180Nov 17, 2025Updated 8 months ago
- A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representat…☆54Jul 13, 2026Updated last week
- Lightweight binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy. Designed for red team operations and ephe…☆569Oct 3, 2025Updated 9 months ago
- Enumerate active EDR's on the system☆153Sep 23, 2025Updated 9 months ago
- ☆50Oct 14, 2025Updated 9 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Overview of MS Defender☆155Feb 20, 2026Updated 5 months ago
- Secrets scanner with a twist... this is for getting threat actor credentials from MALWARE. Acquire TA creds from FLOSS exports, memdumps…☆37Jun 19, 2026Updated last month
- ☆146Sep 9, 2025Updated 10 months ago
- DCOM in memory and fileless lateral movement techniques through .Net deserilization☆273Jun 22, 2026Updated 3 weeks ago
- Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. Implemented in C#…☆371Feb 2, 2026Updated 5 months ago
- Crystal Palace RDLL loader for Adaptix C2 with Ekko sleep obfuscation, IAT hooking via PICO, and per-section permission restoration☆156Jun 5, 2026Updated last month
- A tool for folks who `git clone` first and ask questions later☆71Apr 15, 2026Updated 3 months ago
- Local SYSTEM auth trigger for relaying☆173Jul 22, 2025Updated 11 months ago
- Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but fo…☆173Jun 19, 2026Updated last month
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- A Beacon Object File (BOF) for Havoc/CS to Bypass PPL and Dump Lsass☆180Sep 22, 2025Updated 9 months ago
- BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation☆132Mar 27, 2026Updated 3 months ago
- SimpleCrypt is a powerful command-line tool designed for securely encrypting and decrypting files and directories using AES-256 encryptio…☆20Mar 22, 2026Updated 3 months ago
- Phantom is project created to perform loading and executing unmanaged code in memory within an IIS environment running in full‑trust mode…☆107Jun 5, 2026Updated last month
- MDE/MDI Defender setup for Ludus☆61Mar 14, 2026Updated 4 months ago
- A Payload Analysis Framework☆123Oct 9, 2025Updated 9 months ago
- A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.☆139Jan 28, 2026Updated 5 months ago
- MAD-CAT (Meow Attack Data Corruption Automation Tool) is a comprehensive security tool designed to simulate data corruption attacks again…☆37Oct 11, 2025Updated 9 months ago
- An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard histor…☆114Apr 16, 2026Updated 3 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Locate dlls and function addresses without PEB Walk and EAT parsing☆110Nov 7, 2025Updated 8 months ago
- Lab research on Windows loader internals, PE loading, stack artifacts, and execution tradeoffs.☆237May 4, 2026Updated 2 months ago
- Windows protocol library, including SMB and RPC implementations, among others.☆805Updated this week
- InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution☆162Updated this week
- Self-mutating macOS implant☆138Apr 18, 2026Updated 3 months ago
- Rusty Armory - Beacon Object Files (BOFs) in Rust (Codename: Armory)☆71Apr 3, 2026Updated 3 months ago
- .NET tool used to enrich RPC telemetry☆103Jan 24, 2026Updated 5 months ago