Orchestrate detonating redteam artifacts in VMs with different EDRs to see their detection surface.
☆63Jun 24, 2026Updated last month
Alternatives and similar repositories for detonator
Users that are interested in detonator are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Async BOF that notifies the operator when a user connects to a local or remote target system.☆34Updated this week
- Busybox-style Beacon Object Files for *nix post-exploitation. Reimplements common Unix utilities as BOFs for use in stripped environments…☆83Jul 5, 2026Updated 3 weeks ago
- some research on EDR deconditioning☆15Jun 4, 2026Updated last month
- Windows C/C++ development environment on Linux☆18Mar 29, 2026Updated 3 months ago
- Collect Windows telemetry for Maldev☆494Jun 23, 2026Updated last month
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Windows native ETW inspection suite for browsing providers, reading metadata, consuming live events, recording ETL traces, filtering resu…☆90Updated this week
- Rusty Armory - Beacon Object Files (BOFs) in Rust (Codename: Armory)☆73Apr 3, 2026Updated 3 months ago
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆312Jul 5, 2026Updated 3 weeks ago
- AWS SSO Device-Code Phishing Toolkit for Red / Purple Teams☆23Mar 10, 2026Updated 4 months ago
- (WIP) A Recursive UDRL leveraging smelly_vx's Feverdream trick.☆19Sep 3, 2025Updated 10 months ago
- BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation☆133Mar 27, 2026Updated 4 months ago
- A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.☆166Apr 15, 2026Updated 3 months ago
- Detonate redteam tools on VMs and get logs & detection status☆98Jun 22, 2026Updated last month
- A modern alternative Web-UI for the Mythic Command and Control Server☆79Jul 3, 2026Updated 3 weeks ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Deep insights into EDR detection approaches☆25Updated this week
- Echos is a stealthy C2 traffic emulator built in Rust for Red Teamers. It simulates adversarial beaconing patterns and custom jitter to t…☆34Updated this week
- Linker for Beacon Object Files☆191Updated this week
- One WSL BOF to rule them all☆186Jan 14, 2026Updated 6 months ago
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆276Apr 16, 2026Updated 3 months ago
- Repository hosting a hypothetical EDR Spoofer, as discovered originally by Nightmare-Eclipse☆41May 27, 2026Updated 2 months ago
- This code silently installs Chrome extensions on Mac, Windows, and Linux☆166Jul 22, 2025Updated last year
- A Cobalt Strike BOF implementation of the SilentHarvest registry dumping technique☆182Apr 14, 2026Updated 3 months ago
- Cobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from si…☆92Feb 6, 2026Updated 5 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- open source implementation of the UDC2 spec used in Cobalt Strike☆56Jul 4, 2026Updated 3 weeks ago
- psexec-like remote execution using the paexec wire protocol that supports paexec and remoteexecm2 from manageengine adselfservice plus☆43Mar 24, 2026Updated 4 months ago
- Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.☆23Nov 11, 2025Updated 8 months ago
- Cross-platform CPU-based virtual machine detection framework for modern offensive security.☆48Feb 28, 2026Updated 5 months ago
- Native C++ access to Active Directory over ADWS, no .NET, no WCF, no HTTP stack.☆82Mar 27, 2026Updated 4 months ago
- 🧠 The ultimate resource for finding Beacon Object Files (BOFs).☆149Updated this week
- A Beacon Object File (BOF) for Havoc/CS to Bypass PPL and Dump Lsass☆180Sep 22, 2025Updated 10 months ago
- SOCKS5 proxy tool that uses Azure Storage services as a means of communication.☆360Mar 21, 2026Updated 4 months ago
- A collection of DPAPI hunting and parsing BOFs☆38Mar 3, 2026Updated 4 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution☆162Jul 15, 2026Updated 2 weeks ago
- Tyche is a Mythic HTTPX Profile Generator used to create Malleable C2 Profiles.☆47Mar 28, 2026Updated 4 months ago
- Transform LDAP filters, BaseDNs, attribute lists, and attribute entries using composable middleware chains. Zero dependencies. Works as a…☆44Apr 13, 2026Updated 3 months ago
- A compiled language for Windows position-independent x86-64 shellcode and Beacon Object Files.☆175Jun 28, 2026Updated last month
- Permanently disable EDRs as local admin☆129Dec 19, 2025Updated 7 months ago
- Power Automate C2 (PAC2) : Stealth living-off-the-cloud C2 framework.☆39Apr 16, 2024Updated 2 years ago
- User-mode ETW interception and telemetry manipulation lab for Windows security research.☆43Jun 15, 2026Updated last month