A simple research-focused AES-based shellcode loader demonstrating in-memory execution and NTAPI techniques to help understand how custom loaders can bypass Windows Defender–based detection.
☆51Feb 19, 2026Updated 5 months ago
Alternatives and similar repositories for shellcoderunner
Users that are interested in shellcoderunner are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 3 months ago
- Sleep replacement that executes real, varied work to break behavioral pattern matching by EDR and anti-cheat systems☆34Jul 20, 2026Updated 2 weeks ago
- Invoke-SPSI - Simple PowerShell Shellcode Injector☆38Oct 9, 2025Updated 10 months ago
- A tool to easily perform GitLab Device Code Phishing on red team engagements☆51Feb 9, 2026Updated 6 months ago
- Umbrella will protect your shellcode from the rain.☆31Jun 4, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Service Extender for notifying about AdaptixC2 events in Telegram, Slack, Rocket.Char, Discord, and any web platforms, such as ntfy.sh.☆21Mar 4, 2026Updated 5 months ago
- Crystal Palace RDLL loader for Adaptix C2 with Ekko sleep obfuscation, IAT hooking via PICO, and per-section permission restoration☆160Jun 5, 2026Updated 2 months ago
- Kerberos manipulation library in pure Python☆17Jan 31, 2026Updated 6 months ago
- A Bof to dump domain credentials via DRSGetNCChanges, Created for use with the Adaptix C2.☆15Dec 16, 2025Updated 7 months ago
- Python tool to automatically perform SPN-less RBCD attacks.☆132Jan 7, 2026Updated 7 months ago
- Repository hosting a hypothetical EDR Spoofer, as discovered originally by Nightmare-Eclipse☆41May 27, 2026Updated 2 months ago
- Modular User-Defined Reflective Loader (UDRL) built on Crystal Palace for controlled DLL execution and evasion research.☆33Apr 14, 2026Updated 3 months ago
- BYOVD tool for manipulating Windows Protected Process Light (PPL) protection at the kernel level.☆90May 25, 2026Updated 2 months ago
- Aliasr is a modern, feature-rich TUI launcher for pentest commands.☆115Apr 23, 2026Updated 3 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆119Dec 21, 2025Updated 7 months ago
- In-memory BOF implementation of Silent Process Exit LSASS dump via RtlReportSilentProcessExit☆19Apr 14, 2026Updated 3 months ago
- ☆23Jul 6, 2025Updated last year
- P2P Communications of Named Pipes☆12Jul 30, 2026Updated last week
- Object file loader implemented as a post-ex DLL for asynchronous BOF execution.☆29Jul 23, 2026Updated 2 weeks ago
- ☆72Apr 20, 2026Updated 3 months ago
- This repository contains a collection of scripts I use regularly for offensive security-related tasks.☆16Mar 9, 2026Updated 5 months ago
- A PoC for the dMSA Active Directory Domain Takeover deemed BadSuccessor☆60Mar 6, 2026Updated 5 months ago
- PolyEngine is an evasive PE packer designed for CTF challenges and low-level Windows security education. It focuses on bypassing EDR and …☆154Updated this week
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Rust rewrite of nanodump, a low-level LSASS memory dumping tool.☆16Feb 22, 2026Updated 5 months ago
- ☆55Feb 12, 2026Updated 5 months ago
- Hides in your attic... I mean process☆24Apr 29, 2026Updated 3 months ago
- A POC for developing BOFs for Sliver, Havoc, Cobalt Strike or most COFFLoaders in Rust.☆76Aug 24, 2025Updated 11 months ago
- Crystal Palace Evasion kit for Sliver☆108Jun 13, 2026Updated last month
- A Mythic agent for Windows written in C☆174Updated this week
- Adapted PE Loader to load a rc4 encrypted mimikatz shellcode into memory with specified arguments before exiting.☆16Jun 2, 2025Updated last year
- Active Directory forensic framework☆16May 18, 2026Updated 2 months ago
- Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.☆66May 4, 2026Updated 3 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Proof-of-concept security demo illustrating how PowerShell can create trusted-looking Windows toast notifications chained together with C…☆18Apr 12, 2026Updated 3 months ago
- In-memory Encrypted Shellcode Execution Suite☆16Jan 26, 2026Updated 6 months ago
- Modify machine code in binaries with alternative x64 assembly opcodes for AV evasion☆231Jul 7, 2026Updated last month
- Capture incoming TGTs in pure PowerShell to avoid using Rubeus☆30Mar 29, 2026Updated 4 months ago
- Dump LSASS via physical memory read primitives in vulnerable kernel drivers☆35Jul 23, 2026Updated 2 weeks ago
- A curated collection of Windows privilege escalation exploits from the Potato family, grown and organized for red teamers, researchers, a…☆27Aug 6, 2025Updated last year
- An (WIP) EDR Evasion tool for x64 Windows & Linux binaries that utilizes Nanomites, written in Rust.☆34May 8, 2026Updated 3 months ago