shellcode transformation tool for YARA evasion
☆62Dec 17, 2025Updated 7 months ago
Alternatives and similar repositories for shellcode-mutator
Users that are interested in shellcode-mutator are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PowerShell module for mapping byte offsets to source context and locating AMSI or Microsoft Defender detection boundaries in text and bin…☆35Jul 13, 2026Updated last week
- A Windows tool that converts LDIF files to BloodHound CE☆31Dec 20, 2025Updated 7 months ago
- Brute Ratel External C2 (Microsoft Teams)☆38Dec 11, 2024Updated last year
- Shellcode injection using the Windows Debugging API☆183Jan 4, 2026Updated 6 months ago
- PPLReaper is a Windows UNSIGNED kernel driver + userland companion tool designed to inspect and manipulate Protected Process Light (PPL) …☆24Mar 4, 2026Updated 4 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆311Jul 5, 2026Updated 2 weeks ago
- Beacon Object File to Enable Chrome DevTools Protocol (CDP)☆116Jul 1, 2026Updated 2 weeks ago
- VDM sig bypass and additional WinAPI stubs☆19Feb 16, 2026Updated 5 months ago
- Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective☆181May 31, 2026Updated last month
- Noradrenaline is a collection of high-performance post-exploitation shared libraries designed for native execution on macOS and Linux end…☆29Jul 6, 2026Updated 2 weeks ago
- Whitepaper☆15Dec 1, 2025Updated 7 months ago
- Evade behavioral analysis by executing malicious code within trusted Microsoft call stacks, patchless hooking library IAT/EAT.☆146Dec 8, 2025Updated 7 months ago
- A Cobalt Strike BOF implementation of the SilentHarvest registry dumping technique☆182Apr 14, 2026Updated 3 months ago
- An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard histor…☆114Apr 16, 2026Updated 3 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- New 0 day vulnerability allowing to leak NTLM hashes from browsers with one click☆209Nov 18, 2025Updated 8 months ago
- **CVE-2026-2636** is a vulnerability in the Windows Common Log File System (CLFS) driver (`CLFS.sys`). An unprivileged user can trigger a…☆15Feb 26, 2026Updated 4 months ago
- Proxy function calls through the thread pool with ease☆31Feb 27, 2025Updated last year
- Encode shellcode as XML-looking data. Single-header C library with a two-stage PIC loader example.☆15Feb 11, 2026Updated 5 months ago
- A tool that helps change the recovery configuration of a Windows service to make lateral movement more stealthy☆43Feb 8, 2026Updated 5 months ago
- Dump LSASS via physical memory read primitives in vulnerable kernel drivers☆35Feb 25, 2026Updated 4 months ago
- Indirect-Shellcode-Executor expoits the miss-configuration/vulnerability present on the API Windows method ReadProcessMemory discovered b…☆85Nov 15, 2025Updated 8 months ago
- A professional Red Team / Pentest tool for assessing the external perimeter of a company in a complete "black box" mode (zero knowledge, …☆29Feb 15, 2026Updated 5 months ago
- Beacon Object File (BOF) for Windows Session Hijacking via IHxHelpPaneServer COM☆71Dec 25, 2025Updated 6 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Bof of RegPwn by MDSec☆127Mar 15, 2026Updated 4 months ago
- Experimentations with the MSBuild Capabilites in a default environment.☆23Dec 6, 2025Updated 7 months ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago
- Using Chromium-based browsers as a proxy for C2 traffic.☆155Dec 6, 2025Updated 7 months ago
- Windows Access token manipulation tool made in C#☆25Aug 24, 2025Updated 10 months ago
- ☆85Feb 12, 2026Updated 5 months ago
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.☆56Mar 30, 2026Updated 3 months ago
- Remote service-staging tool built on Impacket, designed for BOF-style lateral movement workflows that lets you upload custom service load…☆124Dec 7, 2025Updated 7 months ago
- A Cobalt Strike RL built with Crystal Palac; module overloading, NtContinue entry transfer, call stack spoofing, sleep masking, and stati…☆226Mar 15, 2026Updated 4 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆102Jan 2, 2026Updated 6 months ago
- Windows Session Hijacking via COM☆349Dec 13, 2025Updated 7 months ago
- Execute shellcode via ASPNET compiler☆61Oct 2, 2025Updated 9 months ago
- EDR-Redir : a tool used to redirect the EDR's folder to another location.☆236May 23, 2026Updated last month
- EDRStartupHinder: A red team tool to prevent Antivirus and EDR from running.☆193May 23, 2026Updated last month
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆120Dec 21, 2025Updated 6 months ago
- BOF to run PE in Cobalt Strike Beacon without console creation☆199Nov 23, 2025Updated 7 months ago