ShellCode 解释器 (样例),无可执行权限加载 ShellCode (点点 Star,非常感谢!)
☆29Mar 7, 2025Updated last year
Alternatives and similar repositories for ShellCode-Interpreter
Users that are interested in ShellCode-Interpreter are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- In-depth reverse engineering of a suspected LockBit affiliate dropper, documenting shellcode loading, import polymorphism, and payload de…☆15Jan 24, 2026Updated 8 months ago
- A Windows C++ OLE/COM Object explorer written in WTL.☆16Feb 28, 2025Updated last year
- ☆20Feb 27, 2022Updated 4 years ago
- 自定义函数堆栈,从而绕过ETW检测,这个是完整版。☆13Apr 15, 2024Updated 2 years ago
- Modified Version of Melkor @FuzzySecurity capable of creating disposable AppDomains in injected processes.☆27Sep 8, 2021Updated 5 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- WebStrike 是一套以 Chromium 系浏览器扩展(Manifest V3) 为受控端点的指挥与控制(C2)套件。与传统以进程/驱动为主的 C2 相比,其工作重心落在 浏览器安全域:在合规授权与攻防演练场景下,可显著降低与终端 EDR 在 进程注入、驱动、内核回调…☆87Jul 8, 2026Updated 2 months ago
- 内存加载执行golang elf二进制文件☆28Dec 22, 2021Updated 4 years ago
- ☆70Jul 12, 2026Updated 2 months ago
- 滴水中级内核学习☆53Mar 12, 2023Updated 3 years ago
- use python on windows with full submodule support without installation☆30Jan 23, 2025Updated last year
- BOF implementation of Adopt. Spawns a process from a process. Can sometimes be used to run a session > 0 process from session 0.☆16Jul 22, 2022Updated 4 years ago
- Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. In C#, C++, Cryst…☆386Aug 31, 2026Updated last month
- Simulate per-process disconnection in red team environments☆116Jun 6, 2025Updated last year
- PoC for covert persistence via Windows Push Task Scheduler (WPTaskScheduler) RPC interface — invisible to schtasks, Get-ScheduledTask, an…☆77Jun 15, 2026Updated 3 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A lightweight Windows Prefetch file parser to extract programs' execution history☆71Jan 12, 2026Updated 8 months ago
- 内网渗透、工具开发、二进制等相关笔记☆12Mar 26, 2023Updated 3 years ago
- A tool for loading and executing PE on Windows and ELF on Linux from memory written in Rust☆15Apr 9, 2025Updated last year
- EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies☆49Jun 8, 2026Updated 3 months ago
- Havoc BOF implementation of BYOVD attack to terminate PPL-protected EDR processes using a signed Microsoft kernel driver.☆39Apr 6, 2026Updated 5 months ago
- A basic C2 framework written in C☆61Jul 7, 2024Updated 2 years ago
- ☆67Jul 6, 2026Updated 2 months ago
- Extracted lua script from Defender mpavbase.vdm and mpasbase.vdm☆15Jul 5, 2024Updated 2 years ago
- 关于RPC一些绕EDR的tips☆200Mar 3, 2023Updated 3 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Server/Client SOCKS5 (RFC 1928) in Reverse mode on Windows☆39Feb 18, 2019Updated 7 years ago
- A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation☆18Dec 18, 2024Updated last year
- A simple parser(library) which extracts shimcache data from windows.☆15May 20, 2019Updated 7 years ago
- 通过分析流量,快速检查手机是否被APT攻击☆35Oct 19, 2025Updated 11 months ago
- Windows绕过EDR实现DumpHash☆262Jul 30, 2026Updated 2 months ago
- GateSentinel 是一个现代化的 C2 (Command and Control) 框架,专为安全研究和渗透测试设计。该项目采用 Go 语言开发服务端,C 语言开发客户端,提供了强大的远程控制和管理功能。☆290Jul 17, 2025Updated last year
- (This is a fork used primarily to submit patches into upstream repository) RpcView is a free tool to explore and decompile Microsoft RPC …☆18May 27, 2023Updated 3 years ago
- Async port/ping scanner BOF. Supports IP/port ranges, CIDR notation and hostnames.☆17Jul 23, 2026Updated 2 months ago
- 一个demo☆24Apr 2, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆16Jan 15, 2026Updated 8 months ago
- A Proof-of-Concept bootkit and UEFI boot application inspired by Petya ransomware, written in Assembly, C, and C++☆277Sep 11, 2026Updated 3 weeks ago
- 使用 rust 实现 CobaltStrike 的 beacon || Using Rust to implement CobaltStrike's Beacon☆208Jul 5, 2025Updated last year
- ☆19Jul 23, 2023Updated 3 years ago
- Advanced OPSEC fork of Donut. Features a Custom in-memory CLR Host, Tail-Jump ETW bypasses, and zero-patch AMSI evasion for stealthy shel…☆74Jun 24, 2026Updated 3 months ago
- Loader Pre-Technology, Main thread hijacking without using API, get ntdll and kernel32 handle without peb. 加载器前置技术,不使用API进行主线程劫持,不使用PEB…☆93Jul 26, 2025Updated last year
- Bypass EDR Create TaskServers☆38Dec 24, 2022Updated 3 years ago