first public in-process reflective PE loader for .NET NativeAOT binaries. maps a NativeAOT executable into the current process and executes it, bypassing the standard Windows loader.
☆28Mar 28, 2026Updated 4 months ago
Alternatives and similar repositories for NativeAOT-RunPE
Users that are interested in NativeAOT-RunPE are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- psexec-like remote execution using the paexec wire protocol that supports paexec and remoteexecm2 from manageengine adselfservice plus☆43Mar 24, 2026Updated 4 months ago
- .NET CLR-Stomping☆147May 20, 2026Updated 2 months ago
- Havoc Professional backend plugin to allow ingesting of events and logs to Ghostwriter☆16Feb 25, 2026Updated 5 months ago
- SharpDPAPI ported to Cobalt Strike BOFs — 19 self-contained BOFs for DPAPI credential triage☆17Feb 24, 2026Updated 5 months ago
- Injecting code by recompiling shellcode into a ROP chain.☆144Apr 21, 2026Updated 3 months ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation☆133Mar 27, 2026Updated 4 months ago
- Busybox-style Beacon Object Files for *nix post-exploitation. Reimplements common Unix utilities as BOFs for use in stripped environments…☆83Jul 5, 2026Updated 3 weeks ago
- A POC tool for exploring dev-tunnels☆66May 5, 2026Updated 2 months ago
- low-level windows networking library using afd.sys sockets and schannel tls. bypasses winsock, winhttp, wininet and other high-level netw…☆16Jul 15, 2026Updated 2 weeks ago
- ☆68Jul 14, 2026Updated 2 weeks ago
- Rusty DoublePulsar - Cobalt Strike User-Defined Reflective Loader (UDRL) in Rust (Codename: DoublePulsar)☆121May 14, 2026Updated 2 months ago
- Intel 64/Windows low-level experiments☆108Jul 21, 2026Updated last week
- A simple OAuth App designed to capture OAuth tokens when users authenticate through GitHub OAuth flow.☆26Apr 20, 2026Updated 3 months ago
- Simple error lookup for Win32 and NTSTATUS errors☆20Nov 25, 2018Updated 7 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Beacon Object File (BOF) to obtain Entra tokens via authcode flow.☆140Jan 17, 2026Updated 6 months ago
- Windows Thread Pool Injection Havoc Implementation☆35Mar 23, 2024Updated 2 years ago
- Hooking KPRCB IdlePreselect function to gain execution inside PID 0.☆80Apr 13, 2025Updated last year
- A credential extraction BOF for Veeam Backup and Replication and Veeam One☆79Jul 1, 2026Updated last month
- A compiled language for Windows position-independent x86-64 shellcode and Beacon Object Files.☆176Jun 28, 2026Updated last month
- ☆12Apr 23, 2019Updated 7 years ago
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆50Jul 23, 2026Updated last week
- BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys.☆83Apr 11, 2026Updated 3 months ago
- Havoc C2 BOF — WFP kernel-space SYSTEM escalation + command execution with indirect syscalls, patchless AMSI/ETW bypass, and return addre…☆80Mar 22, 2026Updated 4 months ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- Azure Blob Storage C2 Profile for Mythic☆30Jan 30, 2026Updated 6 months ago
- ASPX Web Shell with COFF Loader☆134Mar 10, 2026Updated 4 months ago
- BOF for Havoc that copies locked Windows files (SAM, SYSTEM, NTDS.dit) via raw MFT parsing — no VSS, no Registry APIs, no PowerShell☆134Apr 6, 2026Updated 3 months ago
- ☆31Apr 2, 2026Updated 4 months ago
- Windows C/C++ development environment on Linux☆18Mar 29, 2026Updated 4 months ago
- Dumping App Bound Protected Credentials & Cookies Without Privileges.☆169May 28, 2025Updated last year
- JA4 proxy tooling.☆26Feb 10, 2026Updated 5 months ago
- Windows x64 Process Injection via Ghostwriting with Dynamic Configuration☆30Oct 29, 2021Updated 4 years ago
- 无模块注入工程 VS2008☆11Jul 23, 2018Updated 8 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- ☆86Feb 12, 2026Updated 5 months ago
- ntoskrnl .data hooks for UM-KM communication☆52May 26, 2024Updated 2 years ago
- A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.☆140Jan 28, 2026Updated 6 months ago
- Beacon Object File to Enable Chrome DevTools Protocol (CDP)☆116Jul 1, 2026Updated last month
- Windows Portable Device COM BOF☆18Mar 30, 2026Updated 4 months ago
- A Rust template for writing Beacon Object Files (BOFs)☆129Feb 11, 2026Updated 5 months ago
- In-depth reverse engineering of a suspected LockBit affiliate dropper, documenting shellcode loading, import polymorphism, and payload de…☆15Jan 24, 2026Updated 6 months ago