A simple research-focused AES-based shellcode loader demonstrating in-memory execution and NTAPI techniques to help understand how custom loaders can bypass Windows Defender–based detection.
☆52Feb 19, 2026Updated 6 months ago
Alternatives and similar repositories for shellcoderunner
Users that are interested in shellcoderunner are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 3 months ago
- Sleep replacement that executes real, varied work to break behavioral pattern matching by EDR and anti-cheat systems☆78Jul 20, 2026Updated last month
- Invoke-SPSI - Simple PowerShell Shellcode Injector☆38Oct 9, 2025Updated 10 months ago
- A tool to easily perform GitLab Device Code Phishing on red team engagements☆52Feb 9, 2026Updated 6 months ago
- Umbrella will protect your shellcode from the rain.☆31Jun 4, 2025Updated last year
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Service Extender for notifying about AdaptixC2 events in Telegram, Slack, Rocket.Char, Discord, and any web platforms, such as ntfy.sh.☆22Mar 4, 2026Updated 5 months ago
- Crystal Palace RDLL loader for Adaptix C2 with Ekko sleep obfuscation, IAT hooking via PICO, and per-section permission restoration☆159Jun 5, 2026Updated 2 months ago
- Kerberos manipulation library in pure Python☆22Updated this week
- A Bof to dump domain credentials via DRSGetNCChanges, Created for use with the Adaptix C2.☆16Dec 16, 2025Updated 8 months ago
- Python tool to automatically perform SPN-less RBCD attacks.☆132Jan 7, 2026Updated 7 months ago
- Repository hosting a hypothetical EDR Spoofer, as discovered originally by Nightmare-Eclipse☆43May 27, 2026Updated 3 months ago
- Modular User-Defined Reflective Loader (UDRL) built on Crystal Palace for controlled DLL execution and evasion research.☆34Apr 14, 2026Updated 4 months ago
- BYOVD tool for manipulating Windows Protected Process Light (PPL) protection at the kernel level.☆95May 25, 2026Updated 3 months ago
- Aliasr is a modern, feature-rich TUI launcher for pentest commands.☆117Apr 23, 2026Updated 4 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆119Dec 21, 2025Updated 8 months ago
- In-memory BOF implementation of Silent Process Exit LSASS dump via RtlReportSilentProcessExit☆19Apr 14, 2026Updated 4 months ago
- ☆23Jul 6, 2025Updated last year
- Object file loader implemented as a post-ex DLL for asynchronous BOF execution.☆29Jul 23, 2026Updated last month
- P2P Communications of Named Pipes☆12Jul 30, 2026Updated 3 weeks ago
- ☆73Apr 20, 2026Updated 4 months ago
- This repository contains a collection of scripts I use regularly for offensive security-related tasks.☆16Mar 9, 2026Updated 5 months ago
- A PoC for the dMSA Active Directory Domain Takeover deemed BadSuccessor☆61Mar 6, 2026Updated 5 months ago
- PolyEngine is an evasive PE packer designed for CTF challenges and low-level Windows security education. It focuses on bypassing EDR and …☆156Aug 6, 2026Updated 3 weeks ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Rust rewrite of nanodump, a low-level LSASS memory dumping tool.☆16Feb 22, 2026Updated 6 months ago
- ☆55Feb 12, 2026Updated 6 months ago
- Hides in your attic... I mean process☆24Apr 29, 2026Updated 4 months ago
- A POC for developing BOFs for Sliver, Havoc, Cobalt Strike or most COFFLoaders in Rust.☆76Aug 24, 2025Updated last year
- Crystal Palace Evasion kit for Sliver☆113Jun 13, 2026Updated 2 months ago
- A Mythic agent for Windows written in C☆180Aug 22, 2026Updated last week
- Adapted PE Loader to load a rc4 encrypted mimikatz shellcode into memory with specified arguments before exiting.☆16Jun 2, 2025Updated last year
- Active Directory forensic framework☆16May 18, 2026Updated 3 months ago
- Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.☆66May 4, 2026Updated 3 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Proof-of-concept security demo illustrating how PowerShell can create trusted-looking Windows toast notifications chained together with C…☆18Apr 12, 2026Updated 4 months ago
- In-memory Encrypted Shellcode Execution Suite☆16Jan 26, 2026Updated 7 months ago
- Modify machine code in binaries with alternative x64 assembly opcodes for AV evasion☆236Jul 7, 2026Updated last month
- Capture incoming TGTs in pure PowerShell to avoid using Rubeus☆30Mar 29, 2026Updated 5 months ago
- Dump LSASS via physical memory read primitives in vulnerable kernel drivers☆36Jul 23, 2026Updated last month
- A curated collection of Windows privilege escalation exploits from the Potato family, grown and organized for red teamers, researchers, a…☆29Aug 6, 2025Updated last year
- An (WIP) EDR Evasion tool for x64 Windows & Linux binaries that utilizes Nanomites, written in Rust.☆35May 8, 2026Updated 3 months ago