Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing programmatical access in the VBA object environment to load, decrypt and execute shellcode.
☆742Aug 18, 2023Updated 3 years ago
Alternatives and similar repositories for Ivy
Users that are interested in Ivy are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ScareCrow - Payload creation framework designed around EDR bypass.☆2,888Aug 18, 2023Updated 3 years ago
- Cobalt Strike UDRL for memory scanner evasion.☆1,032Jun 4, 2024Updated 2 years ago
- Inject .NET assemblies into an existing process☆507Jan 19, 2022Updated 4 years ago
- KaynLdr is a Reflective Loader written in C/ASM☆550Dec 3, 2023Updated 2 years ago
- A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!☆1,436Nov 22, 2023Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.☆1,220Apr 16, 2025Updated last year
- A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file form…☆1,215Jun 10, 2024Updated 2 years ago
- evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)☆1,510Dec 21, 2023Updated 2 years ago
- A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementin…☆540Aug 1, 2022Updated 4 years ago
- A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techni…☆1,417Oct 27, 2023Updated 2 years ago
- Template-Driven AV/EDR Evasion Framework☆1,822Nov 3, 2023Updated 2 years ago
- Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll☆517Feb 3, 2022Updated 4 years ago
- Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks b…☆464Mar 8, 2023Updated 3 years ago
- Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods☆1,474Aug 18, 2023Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- PIC lsass dumper using cloned handles☆596Oct 18, 2022Updated 3 years ago
- Module Stomping, No New Thread, HellsGate syscaller, UUID Shellcode Runner for x64 Windows 10!☆448Mar 8, 2023Updated 3 years ago
- RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, …☆498Jan 25, 2022Updated 4 years ago
- A .NET Runtime for Cobalt Strike's Beacon Object Files☆784Sep 4, 2024Updated 2 years ago
- Remote operations commands implemented using Beacon Object Files☆1,186Jul 20, 2026Updated last month
- KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default…☆1,687Aug 6, 2022Updated 4 years ago
- ☆1,847Aug 30, 2024Updated 2 years ago
- ☆207Feb 24, 2022Updated 4 years ago
- Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique☆337Jan 16, 2022Updated 4 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs☆1,233Aug 18, 2023Updated 3 years ago
- FrostByte is a POC project that combines different defense evasion techniques to build better redteam payloads☆382Apr 16, 2022Updated 4 years ago
- A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC☆375May 24, 2022Updated 4 years ago
- The swiss army knife of LSASS dumping☆2,138Sep 17, 2024Updated 2 years ago
- Nim-based assembly packer and shellcode loader for opsec & profit☆486Feb 24, 2023Updated 3 years ago
- Framework for Kerberos relaying☆955May 29, 2022Updated 4 years ago
- ☆535Nov 20, 2021Updated 4 years ago
- Open-Source Shellcode & PE Packer☆2,135Feb 3, 2024Updated 2 years ago
- ☆2,205Apr 3, 2026Updated 5 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- OfensivePipeline allows you to download and build C# tools, applying certain modifications in order to improve their evasion for Red Team…☆821Jun 5, 2026Updated 3 months ago
- This repo covers some code execution and AV Evasion methods for Macros in Office documents☆1,276Jan 27, 2022Updated 4 years ago
- Convert shellcode into different formats!☆355Jan 24, 2023Updated 3 years ago
- .NET, PE, & Raw Shellcode Packer/Loader Written in Nim☆825Jan 20, 2023Updated 3 years ago
- SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature…☆1,291Aug 27, 2023Updated 3 years ago
- C# Reflective loader for unmanaged binaries.☆445Jan 25, 2023Updated 3 years ago
- Proof-of-concept obfuscation toolkit for C# post-exploitation tools☆434Jul 22, 2022Updated 4 years ago