Orchestrate detonating redteam artifacts in VMs with different EDRs to see their detection surface.
☆90Sep 7, 2026Updated 3 weeks ago
Alternatives and similar repositories for detonator
Users that are interested in detonator are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- some research on EDR deconditioning☆16Jun 4, 2026Updated 3 months ago
- Busybox-style Beacon Object Files for *nix post-exploitation. Reimplements common Unix utilities as BOFs for use in stripped environments…☆83Aug 22, 2026Updated last month
- Async BOF that notifies the operator when a user connects to a local or remote target system.☆34Jul 30, 2026Updated last month
- Windows C/C++ development environment on Linux☆18Mar 29, 2026Updated 5 months ago
- Collect Windows telemetry for Maldev☆508Aug 14, 2026Updated last month
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- (WIP) A Recursive UDRL leveraging smelly_vx's Feverdream trick.☆19Sep 3, 2025Updated last year
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆319Aug 31, 2026Updated 3 weeks ago
- Windows native ETW inspection suite for browsing providers, reading metadata, consuming live events, recording ETL traces, filtering resu…☆112Jul 27, 2026Updated 2 months ago
- Detonate redteam tools on VMs and get logs & detection status☆107Updated this week
- Rust Armory - Cobalt Strike Beacon Object Files (BOFs) in Rust for situational awareness, remote operations, and post-exploitation tradec…☆71Sep 17, 2026Updated last week
- Deep insights into EDR detection approaches☆102Aug 23, 2026Updated last month
- A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.☆167Apr 15, 2026Updated 5 months ago
- AWS SSO Device-Code Phishing Toolkit for Red / Purple Teams☆23Mar 10, 2026Updated 6 months ago
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆281Apr 16, 2026Updated 5 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A modern alternative Web-UI for the Mythic Command and Control Server☆82Jul 3, 2026Updated 2 months ago
- psexec-like remote execution using the paexec wire protocol that supports paexec and remoteexecm2 from manageengine adselfservice plus☆44Mar 24, 2026Updated 6 months ago
- Linker for Beacon Object Files☆192Sep 16, 2026Updated last week
- One WSL BOF to rule them all☆189Jan 14, 2026Updated 8 months ago
- Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.☆23Nov 11, 2025Updated 10 months ago
- This code silently installs Chrome extensions on Mac, Windows, and Linux☆179Aug 6, 2026Updated last month
- A Beacon Object File (BOF) for Havoc/CS to Bypass PPL and Dump Lsass☆178Sep 22, 2025Updated last year
- Echos is a stealthy C2 traffic emulator built in Rust for Red Teamers. It simulates adversarial beaconing patterns and custom jitter to t…☆33Jul 28, 2026Updated 2 months ago
- open source implementation of the UDC2 spec used in Cobalt Strike☆59Jul 4, 2026Updated 2 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A Cobalt Strike BOF implementation of the SilentHarvest registry dumping technique☆182Apr 14, 2026Updated 5 months ago
- A collection of DPAPI hunting and parsing BOFs☆39Mar 3, 2026Updated 6 months ago
- Cobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from si…☆97Feb 6, 2026Updated 7 months ago
- Repository hosting a hypothetical EDR Spoofer, as discovered originally by Nightmare-Eclipse☆43May 27, 2026Updated 4 months ago
- 🧠 The ultimate resource for finding Beacon Object Files (BOFs).☆161Sep 21, 2026Updated last week
- Power Automate C2 (PAC2) : Stealth living-off-the-cloud C2 framework.☆39Apr 16, 2024Updated 2 years ago
- Native C++ access to Active Directory over ADWS, no .NET, no WCF, no HTTP stack.☆83Mar 27, 2026Updated 6 months ago
- sigreturn-oriented(SROP) based sleep obfuscation poc for Linux☆68Dec 15, 2025Updated 9 months ago
- SOCKS5 proxy tool that uses Azure Storage services as a means of communication.☆365Aug 15, 2026Updated last month
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Built for red teamers, by red teamers - an MCP tool for malware development, OPSEC testing, and supporting custom loader design during re…☆47Aug 10, 2025Updated last year
- Lateral movement with DCOM DLL hijacking☆183Jul 4, 2025Updated last year
- Moonwalk++: Simple POC Combining StackMoonwalking and Memory Encryption☆234Dec 17, 2025Updated 9 months ago
- InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution☆321Updated this week
- A compiled language for Windows position-independent x86-64 shellcode and Beacon Object Files.☆244Jun 28, 2026Updated 3 months ago
- Permanently disable EDRs as local admin☆131Dec 19, 2025Updated 9 months ago
- DCOM in memory and fileless lateral movement techniques through .Net deserilization☆293Jun 22, 2026Updated 3 months ago