first public in-process reflective PE loader for .NET NativeAOT binaries. maps a NativeAOT executable into the current process and executes it, bypassing the standard Windows loader.
☆28Mar 28, 2026Updated 5 months ago
Alternatives and similar repositories for NativeAOT-RunPE
Users that are interested in NativeAOT-RunPE are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- psexec-like remote execution using the paexec wire protocol that supports paexec and remoteexecm2 from manageengine adselfservice plus☆43Mar 24, 2026Updated 5 months ago
- .NET CLR-Stomping☆148May 20, 2026Updated 3 months ago
- Havoc Professional backend plugin to allow ingesting of events and logs to Ghostwriter☆16Feb 25, 2026Updated 6 months ago
- SharpDPAPI ported to Cobalt Strike BOFs — 19 self-contained BOFs for DPAPI credential triage☆17Feb 24, 2026Updated 6 months ago
- Injecting code by recompiling shellcode into a ROP chain.☆147Apr 21, 2026Updated 4 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Busybox-style Beacon Object Files for *nix post-exploitation. Reimplements common Unix utilities as BOFs for use in stripped environments…☆84Aug 22, 2026Updated 3 weeks ago
- A POC tool for exploring dev-tunnels☆72May 5, 2026Updated 4 months ago
- low-level windows networking library using afd.sys sockets and schannel tls. bypasses winsock, winhttp, wininet and other high-level netw…☆17Jul 15, 2026Updated last month
- A Windows x64 offensive research framework that constructs fully synthetic call stacks☆70Jul 14, 2026Updated last month
- Rusty DoublePulsar - Cobalt Strike User-Defined Reflective Loader (UDRL) in Rust (Codename: DoublePulsar)☆119May 14, 2026Updated 3 months ago
- Intel 64/Windows low-level experiments☆115Aug 26, 2026Updated 2 weeks ago
- A simple OAuth App designed to capture OAuth tokens when users authenticate through GitHub OAuth flow.☆27Apr 20, 2026Updated 4 months ago
- Simple error lookup for Win32 and NTSTATUS errors☆20Nov 25, 2018Updated 7 years ago
- Beacon Object File (BOF) to obtain Entra tokens via authcode flow.☆141Jan 17, 2026Updated 7 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Windows Thread Pool Injection Havoc Implementation☆35Mar 23, 2024Updated 2 years ago
- Hooking KPRCB IdlePreselect function to gain execution inside PID 0.☆81Apr 13, 2025Updated last year
- A credential extraction BOF for Veeam Backup and Replication and Veeam One☆80Jul 1, 2026Updated 2 months ago
- A compiled language for Windows position-independent x86-64 shellcode and Beacon Object Files.☆192Jun 28, 2026Updated 2 months ago
- ☆12Apr 23, 2019Updated 7 years ago
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆51Jul 23, 2026Updated last month
- BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys.☆82Apr 11, 2026Updated 5 months ago
- Azure Blob Storage C2 Profile for Mythic☆30Jan 30, 2026Updated 7 months ago
- BOF for Havoc that copies locked Windows files (SAM, SYSTEM, NTDS.dit) via raw MFT parsing — no VSS, no Registry APIs, no PowerShell☆135Apr 6, 2026Updated 5 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- ASPX Web Shell with COFF Loader☆137Mar 10, 2026Updated 6 months ago
- ☆31Apr 2, 2026Updated 5 months ago
- Windows C/C++ development environment on Linux☆18Mar 29, 2026Updated 5 months ago
- Dumping App Bound Protected Credentials & Cookies Without Privileges.☆172May 28, 2025Updated last year
- JA4 proxy tooling.☆27Feb 10, 2026Updated 7 months ago
- 无模块注入工程 VS2008☆11Jul 23, 2018Updated 8 years ago
- Windows x64 Process Injection via Ghostwriting with Dynamic Configuration☆30Oct 29, 2021Updated 4 years ago
- ☆88Feb 12, 2026Updated 7 months ago
- ntoskrnl .data hooks for UM-KM communication☆53May 26, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.☆145Jan 28, 2026Updated 7 months ago
- Windows Portable Device COM BOF☆17Mar 30, 2026Updated 5 months ago
- A Rust template for writing Beacon Object Files (BOFs)☆132Feb 11, 2026Updated 7 months ago
- In-depth reverse engineering of a suspected LockBit affiliate dropper, documenting shellcode loading, import polymorphism, and payload de…☆15Jan 24, 2026Updated 7 months ago
- Beacon Object File to Enable Chrome DevTools Protocol (CDP)☆128Aug 22, 2026Updated 3 weeks ago
- Bring your own Unwind Data Framework☆172Mar 15, 2026Updated 5 months ago
- AD ACL Abuser for Havoc C2☆25Mar 30, 2026Updated 5 months ago