Orchestrate detonating redteam artifacts in VMs with different EDRs to see their detection surface.
☆87Aug 14, 2026Updated 3 weeks ago
Alternatives and similar repositories for detonator
Users that are interested in detonator are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Async BOF that notifies the operator when a user connects to a local or remote target system.☆34Jul 30, 2026Updated last month
- Busybox-style Beacon Object Files for *nix post-exploitation. Reimplements common Unix utilities as BOFs for use in stripped environments…☆84Aug 22, 2026Updated 2 weeks ago
- some research on EDR deconditioning☆16Jun 4, 2026Updated 3 months ago
- Windows C/C++ development environment on Linux☆18Mar 29, 2026Updated 5 months ago
- Collect Windows telemetry for Maldev☆508Aug 14, 2026Updated 3 weeks ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Windows native ETW inspection suite for browsing providers, reading metadata, consuming live events, recording ETL traces, filtering resu…☆111Jul 27, 2026Updated last month
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆316Aug 31, 2026Updated last week
- Rusty Armory - Beacon Object Files (BOFs) in Rust (Codename: Armory)☆72Apr 3, 2026Updated 5 months ago
- AWS SSO Device-Code Phishing Toolkit for Red / Purple Teams☆23Mar 10, 2026Updated 5 months ago
- (WIP) A Recursive UDRL leveraging smelly_vx's Feverdream trick.☆19Sep 3, 2025Updated last year
- BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation☆137Mar 27, 2026Updated 5 months ago
- A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.☆168Apr 15, 2026Updated 4 months ago
- Detonate redteam tools on VMs and get logs & detection status☆106Aug 14, 2026Updated 3 weeks ago
- A modern alternative Web-UI for the Mythic Command and Control Server☆83Jul 3, 2026Updated 2 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Deep insights into EDR detection approaches☆98Aug 23, 2026Updated 2 weeks ago
- Echos is a stealthy C2 traffic emulator built in Rust for Red Teamers. It simulates adversarial beaconing patterns and custom jitter to t…☆34Jul 28, 2026Updated last month
- One WSL BOF to rule them all☆190Jan 14, 2026Updated 7 months ago
- Linker for Beacon Object Files☆191Aug 14, 2026Updated 3 weeks ago
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆281Apr 16, 2026Updated 4 months ago
- Repository hosting a hypothetical EDR Spoofer, as discovered originally by Nightmare-Eclipse☆43May 27, 2026Updated 3 months ago
- This code silently installs Chrome extensions on Mac, Windows, and Linux☆183Aug 6, 2026Updated last month
- A Cobalt Strike BOF implementation of the SilentHarvest registry dumping technique☆183Apr 14, 2026Updated 4 months ago
- Cobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from si…☆95Feb 6, 2026Updated 7 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- open source implementation of the UDC2 spec used in Cobalt Strike☆59Jul 4, 2026Updated 2 months ago
- psexec-like remote execution using the paexec wire protocol that supports paexec and remoteexecm2 from manageengine adselfservice plus☆43Mar 24, 2026Updated 5 months ago
- Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.☆23Nov 11, 2025Updated 9 months ago
- Native C++ access to Active Directory over ADWS, no .NET, no WCF, no HTTP stack.☆83Mar 27, 2026Updated 5 months ago
- 🧠 The ultimate resource for finding Beacon Object Files (BOFs).☆158Updated this week
- A Beacon Object File (BOF) for Havoc/CS to Bypass PPL and Dump Lsass☆178Sep 22, 2025Updated 11 months ago
- SOCKS5 proxy tool that uses Azure Storage services as a means of communication.☆364Aug 15, 2026Updated 3 weeks ago
- A collection of DPAPI hunting and parsing BOFs☆40Mar 3, 2026Updated 6 months ago
- Tyche is a Mythic HTTPX Profile Generator used to create Malleable C2 Profiles.☆53Mar 28, 2026Updated 5 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Transform LDAP filters, BaseDNs, attribute lists, and attribute entries using composable middleware chains. Zero dependencies. Works as a…☆44Apr 13, 2026Updated 4 months ago
- A compiled language for Windows position-independent x86-64 shellcode and Beacon Object Files.☆188Jun 28, 2026Updated 2 months ago
- InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution☆310Aug 22, 2026Updated 2 weeks ago
- Permanently disable EDRs as local admin☆128Dec 19, 2025Updated 8 months ago
- Power Automate C2 (PAC2) : Stealth living-off-the-cloud C2 framework.☆39Apr 16, 2024Updated 2 years ago
- User-mode ETW interception and telemetry manipulation lab for Windows security research.☆44Jun 15, 2026Updated 2 months ago
- sigreturn-oriented(SROP) based sleep obfuscation poc for Linux☆69Dec 15, 2025Updated 8 months ago