shellcode transformation tool for YARA evasion
☆62Dec 17, 2025Updated 8 months ago
Alternatives and similar repositories for shellcode-mutator
Users that are interested in shellcode-mutator are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus …☆83Jul 28, 2026Updated last month
- A Windows tool that converts LDIF files to BloodHound CE☆31Dec 20, 2025Updated 8 months ago
- Brute Ratel External C2 (Microsoft Teams)☆38Dec 11, 2024Updated last year
- Shellcode injection using the Windows Debugging API☆182Jan 4, 2026Updated 7 months ago
- PPLReaper is a Windows UNSIGNED kernel driver + userland companion tool designed to inspect and manipulate Protected Process Light (PPL) …☆24Mar 4, 2026Updated 5 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆316Updated this week
- Beacon Object File to Enable Chrome DevTools Protocol (CDP)☆126Aug 22, 2026Updated last week
- VDM sig bypass and additional WinAPI stubs☆20Feb 16, 2026Updated 6 months ago
- GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumera…☆43Aug 9, 2026Updated 2 weeks ago
- Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective☆189May 31, 2026Updated 2 months ago
- Noradrenaline is a collection of high-performance post-exploitation shared libraries designed for native execution on macOS and Linux end…☆30Jul 6, 2026Updated last month
- Whitepaper☆16Dec 1, 2025Updated 8 months ago
- Evade behavioral analysis by executing malicious code within trusted Microsoft call stacks, patchless hooking library IAT/EAT.☆149Dec 8, 2025Updated 8 months ago
- A Cobalt Strike BOF implementation of the SilentHarvest registry dumping technique☆183Apr 14, 2026Updated 4 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard histor…☆117Apr 16, 2026Updated 4 months ago
- New 0 day vulnerability allowing to leak NTLM hashes from browsers with one click☆210Nov 18, 2025Updated 9 months ago
- **CVE-2026-2636** is a vulnerability in the Windows Common Log File System (CLFS) driver (`CLFS.sys`). An unprivileged user can trigger a…☆15Feb 26, 2026Updated 6 months ago
- Proxy function calls through the thread pool with ease☆31Feb 27, 2025Updated last year
- A tool that helps change the recovery configuration of a Windows service to make lateral movement more stealthy☆43Feb 8, 2026Updated 6 months ago
- Encode shellcode as XML-looking data. Single-header C library with a two-stage PIC loader example.☆15Feb 11, 2026Updated 6 months ago
- Dump LSASS via physical memory read primitives in vulnerable kernel drivers☆36Jul 23, 2026Updated last month
- Indirect-Shellcode-Executor expoits the miss-configuration/vulnerability present on the API Windows method ReadProcessMemory discovered b…☆86Nov 15, 2025Updated 9 months ago
- Beacon Object File (BOF) for Windows Session Hijacking via IHxHelpPaneServer COM☆71Dec 25, 2025Updated 8 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Bof of RegPwn by MDSec☆129Mar 15, 2026Updated 5 months ago
- Experimentations with the MSBuild Capabilites in a default environment.☆23Dec 6, 2025Updated 8 months ago
- Using Chromium-based browsers as a proxy for C2 traffic.☆156Dec 6, 2025Updated 8 months ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 4 months ago
- Windows Access token manipulation tool made in C#☆25Aug 24, 2025Updated last year
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.☆55Mar 30, 2026Updated 4 months ago
- ☆87Feb 12, 2026Updated 6 months ago
- Remote service-staging tool built on Impacket, designed for BOF-style lateral movement workflows that lets you upload custom service load…☆127Dec 7, 2025Updated 8 months ago
- A Cobalt Strike RL built with Crystal Palac; module overloading, NtContinue entry transfer, call stack spoofing, sleep masking, and stati…☆255Mar 15, 2026Updated 5 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆102Jan 2, 2026Updated 7 months ago
- Execute shellcode via ASPNET compiler☆61Oct 2, 2025Updated 10 months ago
- Windows Session Hijacking via COM☆349Dec 13, 2025Updated 8 months ago
- EDR-Redir : a tool used to redirect the EDR's folder to another location.☆239May 23, 2026Updated 3 months ago
- EDRStartupHinder: A red team tool to prevent Antivirus and EDR from running.☆195May 23, 2026Updated 3 months ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆119Dec 21, 2025Updated 8 months ago
- BOF to run PE in Cobalt Strike Beacon without console creation☆200Nov 23, 2025Updated 9 months ago