A simple research-focused AES-based shellcode loader demonstrating in-memory execution and NTAPI techniques to help understand how custom loaders can bypass Windows Defender–based detection.
☆49Feb 19, 2026Updated 5 months ago
Alternatives and similar repositories for shellcoderunner
Users that are interested in shellcoderunner are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 2 months ago
- Sleep replacement that executes real, varied work to break behavioral pattern matching by EDR and anti-cheat systems☆34Updated this week
- Invoke-SPSI - Simple PowerShell Shellcode Injector☆38Oct 9, 2025Updated 9 months ago
- A tool to easily perform GitLab Device Code Phishing on red team engagements☆51Feb 9, 2026Updated 5 months ago
- Umbrella will protect your shellcode from the rain.☆31Jun 4, 2025Updated last year
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Service Extender for notifying about AdaptixC2 events in Telegram, Slack, Rocket.Char, Discord, and any web platforms, such as ntfy.sh.☆19Mar 4, 2026Updated 4 months ago
- Crystal Palace RDLL loader for Adaptix C2 with Ekko sleep obfuscation, IAT hooking via PICO, and per-section permission restoration☆156Jun 5, 2026Updated last month
- Kerberos manipulation library in pure Python☆17Jan 31, 2026Updated 5 months ago
- A Bof to dump domain credentials via DRSGetNCChanges, Created for use with the Adaptix C2.☆15Dec 16, 2025Updated 7 months ago
- Python tool to automatically perform SPN-less RBCD attacks.☆132Jan 7, 2026Updated 6 months ago
- Repository hosting a hypothetical EDR Spoofer, as discovered originally by Nightmare-Eclipse☆41May 27, 2026Updated last month
- Modular User-Defined Reflective Loader (UDRL) built on Crystal Palace for controlled DLL execution and evasion research.☆34Apr 14, 2026Updated 3 months ago
- BYOVD tool for manipulating Windows Protected Process Light (PPL) protection at the kernel level.☆88May 25, 2026Updated last month
- Aliasr is a modern, feature-rich TUI launcher for pentest commands.☆114Apr 23, 2026Updated 2 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆120Dec 21, 2025Updated 6 months ago
- In-memory BOF implementation of Silent Process Exit LSASS dump via RtlReportSilentProcessExit☆19Apr 14, 2026Updated 3 months ago
- ☆23Jul 6, 2025Updated last year
- A PoC for the dMSA Active Directory Domain Takeover deemed BadSuccessor☆60Mar 6, 2026Updated 4 months ago
- Object file loader implemented as a post-ex DLL for asynchronous BOF execution.☆29Jun 15, 2026Updated last month
- ☆70Apr 20, 2026Updated 3 months ago
- P2P Communications of Named Pipes☆12Dec 11, 2025Updated 7 months ago
- PolyEngine is an evasive PE packer designed for CTF challenges and low-level Windows security education. It focuses on bypassing EDR and …☆148Jun 10, 2026Updated last month
- Rust rewrite of nanodump, a low-level LSASS memory dumping tool.☆16Feb 22, 2026Updated 4 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆52Feb 12, 2026Updated 5 months ago
- Hides in your attic... I mean process☆24Apr 29, 2026Updated 2 months ago
- A POC for developing BOFs for Sliver, Havoc, Cobalt Strike or most COFFLoaders in Rust.☆76Aug 24, 2025Updated 10 months ago
- Crystal Palace Evasion kit for Sliver☆97Jun 13, 2026Updated last month
- Adapted PE Loader to load a rc4 encrypted mimikatz shellcode into memory with specified arguments before exiting.☆16Jun 2, 2025Updated last year
- Active Directory forensic framework☆16May 18, 2026Updated 2 months ago
- Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.☆62May 4, 2026Updated 2 months ago
- Proof-of-concept security demo illustrating how PowerShell can create trusted-looking Windows toast notifications chained together with C…☆16Apr 12, 2026Updated 3 months ago
- In-memory Encrypted Shellcode Execution Suite☆16Jan 26, 2026Updated 5 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Modify machine code in binaries with alternative x64 assembly opcodes for AV evasion☆228Jul 7, 2026Updated last week
- Dump LSASS via physical memory read primitives in vulnerable kernel drivers☆35Feb 25, 2026Updated 4 months ago
- Capture incoming TGTs in pure PowerShell to avoid using Rubeus☆30Mar 29, 2026Updated 3 months ago
- A curated collection of Windows privilege escalation exploits from the Potato family, grown and organized for red teamers, researchers, a…☆26Aug 6, 2025Updated 11 months ago
- An (WIP) EDR Evasion tool for x64 Windows & Linux binaries that utilizes Nanomites, written in Rust.☆34May 8, 2026Updated 2 months ago
- Async BOF to automatically extract or renew Kerberos TGTs on a target system.☆134Updated this week
- Command channel that uses Wi-Fi Beacons as a Bidirectional C2 transport☆44Mar 28, 2026Updated 3 months ago