shellcode transformation tool for YARA evasion
☆62Dec 17, 2025Updated 7 months ago
Alternatives and similar repositories for shellcode-mutator
Users that are interested in shellcode-mutator are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus …☆81Jul 28, 2026Updated last week
- A Windows tool that converts LDIF files to BloodHound CE☆31Dec 20, 2025Updated 7 months ago
- Brute Ratel External C2 (Microsoft Teams)☆38Dec 11, 2024Updated last year
- Shellcode injection using the Windows Debugging API☆183Jan 4, 2026Updated 7 months ago
- PPLReaper is a Windows UNSIGNED kernel driver + userland companion tool designed to inspect and manipulate Protected Process Light (PPL) …☆24Mar 4, 2026Updated 5 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆312Updated this week
- Beacon Object File to Enable Chrome DevTools Protocol (CDP)☆118Updated this week
- VDM sig bypass and additional WinAPI stubs☆19Feb 16, 2026Updated 5 months ago
- GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumera…☆42Jul 23, 2026Updated 2 weeks ago
- Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective☆183May 31, 2026Updated 2 months ago
- Noradrenaline is a collection of high-performance post-exploitation shared libraries designed for native execution on macOS and Linux end…☆30Jul 6, 2026Updated last month
- Whitepaper☆16Dec 1, 2025Updated 8 months ago
- Evade behavioral analysis by executing malicious code within trusted Microsoft call stacks, patchless hooking library IAT/EAT.☆148Dec 8, 2025Updated 8 months ago
- A Cobalt Strike BOF implementation of the SilentHarvest registry dumping technique☆183Apr 14, 2026Updated 3 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard histor…☆114Apr 16, 2026Updated 3 months ago
- New 0 day vulnerability allowing to leak NTLM hashes from browsers with one click☆209Nov 18, 2025Updated 8 months ago
- **CVE-2026-2636** is a vulnerability in the Windows Common Log File System (CLFS) driver (`CLFS.sys`). An unprivileged user can trigger a…☆15Feb 26, 2026Updated 5 months ago
- Proxy function calls through the thread pool with ease☆31Feb 27, 2025Updated last year
- A tool that helps change the recovery configuration of a Windows service to make lateral movement more stealthy☆43Feb 8, 2026Updated 6 months ago
- Encode shellcode as XML-looking data. Single-header C library with a two-stage PIC loader example.☆15Feb 11, 2026Updated 5 months ago
- Dump LSASS via physical memory read primitives in vulnerable kernel drivers☆35Jul 23, 2026Updated 2 weeks ago
- Indirect-Shellcode-Executor expoits the miss-configuration/vulnerability present on the API Windows method ReadProcessMemory discovered b…☆86Nov 15, 2025Updated 8 months ago
- Beacon Object File (BOF) for Windows Session Hijacking via IHxHelpPaneServer COM☆71Dec 25, 2025Updated 7 months ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Bof of RegPwn by MDSec☆127Mar 15, 2026Updated 4 months ago
- A professional Red Team / Pentest tool for assessing the external perimeter of a company in a complete "black box" mode (zero knowledge, …☆29Feb 15, 2026Updated 5 months ago
- Experimentations with the MSBuild Capabilites in a default environment.☆23Dec 6, 2025Updated 8 months ago
- Using Chromium-based browsers as a proxy for C2 traffic.☆156Dec 6, 2025Updated 8 months ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago
- Windows Access token manipulation tool made in C#☆25Aug 24, 2025Updated 11 months ago
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.☆56Mar 30, 2026Updated 4 months ago
- ☆86Feb 12, 2026Updated 5 months ago
- Remote service-staging tool built on Impacket, designed for BOF-style lateral movement workflows that lets you upload custom service load…☆127Dec 7, 2025Updated 8 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A Cobalt Strike RL built with Crystal Palac; module overloading, NtContinue entry transfer, call stack spoofing, sleep masking, and stati…☆232Mar 15, 2026Updated 4 months ago
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆102Jan 2, 2026Updated 7 months ago
- Execute shellcode via ASPNET compiler☆61Oct 2, 2025Updated 10 months ago
- Windows Session Hijacking via COM☆349Dec 13, 2025Updated 7 months ago
- EDR-Redir : a tool used to redirect the EDR's folder to another location.☆236May 23, 2026Updated 2 months ago
- EDRStartupHinder: A red team tool to prevent Antivirus and EDR from running.☆195May 23, 2026Updated 2 months ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆119Dec 21, 2025Updated 7 months ago