shellcode transformation tool for YARA evasion
☆62Dec 17, 2025Updated 9 months ago
Alternatives and similar repositories for shellcode-mutator
Users that are interested in shellcode-mutator are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus …☆86Jul 28, 2026Updated last month
- A Windows tool that converts LDIF files to BloodHound CE☆31Dec 20, 2025Updated 8 months ago
- PPLReaper is a Windows UNSIGNED kernel driver + userland companion tool designed to inspect and manipulate Protected Process Light (PPL) …☆25Mar 4, 2026Updated 6 months ago
- Brute Ratel External C2 (Microsoft Teams)☆38Dec 11, 2024Updated last year
- Shellcode injection using the Windows Debugging API☆181Jan 4, 2026Updated 8 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆317Aug 31, 2026Updated 2 weeks ago
- Beacon Object File to Enable Chrome DevTools Protocol (CDP)☆128Aug 22, 2026Updated 3 weeks ago
- GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumera…☆44Aug 9, 2026Updated last month
- Noradrenaline is a collection of high-performance post-exploitation shared libraries designed for native execution on macOS and Linux end…☆32Sep 1, 2026Updated 2 weeks ago
- VDM sig bypass and additional WinAPI stubs☆19Feb 16, 2026Updated 7 months ago
- Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective☆190May 31, 2026Updated 3 months ago
- Whitepaper☆16Dec 1, 2025Updated 9 months ago
- Evade behavioral analysis by executing malicious code within trusted Microsoft call stacks, patchless hooking library IAT/EAT.☆148Dec 8, 2025Updated 9 months ago
- A Cobalt Strike BOF implementation of the SilentHarvest registry dumping technique☆181Apr 14, 2026Updated 5 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard histor…☆117Apr 16, 2026Updated 5 months ago
- New 0 day vulnerability allowing to leak NTLM hashes from browsers with one click☆208Nov 18, 2025Updated 10 months ago
- **CVE-2026-2636** is a vulnerability in the Windows Common Log File System (CLFS) driver (`CLFS.sys`). An unprivileged user can trigger a…☆15Feb 26, 2026Updated 6 months ago
- Proxy function calls through the thread pool with ease☆31Feb 27, 2025Updated last year
- A tool that helps change the recovery configuration of a Windows service to make lateral movement more stealthy☆44Feb 8, 2026Updated 7 months ago
- Encode shellcode as XML-looking data. Single-header C library with a two-stage PIC loader example.☆15Feb 11, 2026Updated 7 months ago
- Dump LSASS via physical memory read primitives in vulnerable kernel drivers☆35Jul 23, 2026Updated last month
- Indirect-Shellcode-Executor expoits the miss-configuration/vulnerability present on the API Windows method ReadProcessMemory discovered b…☆86Nov 15, 2025Updated 10 months ago
- Beacon Object File (BOF) for Windows Session Hijacking via IHxHelpPaneServer COM☆71Dec 25, 2025Updated 8 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Bof of RegPwn by MDSec☆129Mar 15, 2026Updated 6 months ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 5 months ago
- Experimentations with the MSBuild Capabilites in a default environment.☆24Dec 6, 2025Updated 9 months ago
- Using Chromium-based browsers as a proxy for C2 traffic.☆155Dec 6, 2025Updated 9 months ago
- Windows Access token manipulation tool made in C#☆25Aug 24, 2025Updated last year
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.☆55Mar 30, 2026Updated 5 months ago
- ☆88Feb 12, 2026Updated 7 months ago
- Remote service-staging tool built on Impacket, designed for BOF-style lateral movement workflows that lets you upload custom service load…☆128Dec 7, 2025Updated 9 months ago
- A Cobalt Strike RL built with Crystal Palac; module overloading, NtContinue entry transfer, call stack spoofing, sleep masking, and stati…☆256Mar 15, 2026Updated 6 months ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆101Jan 2, 2026Updated 8 months ago
- Windows Session Hijacking via COM☆350Dec 13, 2025Updated 9 months ago
- Execute shellcode via ASPNET compiler☆60Oct 2, 2025Updated 11 months ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆118Dec 21, 2025Updated 8 months ago
- EDR-Redir : a tool used to redirect the EDR's folder to another location.☆243May 23, 2026Updated 3 months ago
- EDRStartupHinder: A red team tool to prevent Antivirus and EDR from running.☆193May 23, 2026Updated 3 months ago
- BOF to run PE in Cobalt Strike Beacon without console creation☆198Nov 23, 2025Updated 9 months ago