Polymorphic AV/AMSI bypass toolkit - Donut shellcode runner for offensive .NET/PE tools
☆37May 26, 2026Updated 2 months ago
Alternatives and similar repositories for killshot
Users that are interested in killshot are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Automated script for obfuscating, rebranding and renaming the Havoc C2 Framework to evade AV/EDR and C2 hunters.☆49Aug 13, 2025Updated last year
- Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification s…☆42Jun 4, 2026Updated 2 months ago
- A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.☆59Jul 20, 2026Updated last month
- Active Directory forensic framework☆16May 18, 2026Updated 3 months ago
- COM Windows Persistence Technique☆90Apr 27, 2026Updated 3 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advance…☆117Jun 30, 2026Updated last month
- Phantom is project created to perform loading and executing unmanaged code in memory within an IIS environment running in full‑trust mode…☆108Jun 5, 2026Updated 2 months ago
- Evasive loader for .NET Framework assemblies☆46May 14, 2026Updated 3 months ago
- Another BYOVD process killer. works on all EDR's. fully signed.☆290May 19, 2026Updated 3 months ago
- Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.☆67Mar 2, 2026Updated 5 months ago
- A C# PE loader for x64 and x86 PE files.☆57Mar 9, 2026Updated 5 months ago
- Collection of custom implementations about some WinAPI functions☆38Jul 30, 2026Updated 3 weeks ago
- Async port/ping scanner BOF. Supports IP/port ranges, CIDR notation and hostnames.☆18Jul 23, 2026Updated last month
- Python3 tool to perform password spraying using RDP☆17Aug 14, 2023Updated 3 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- IDA Pro plugin to aid with the analysis of native IIS modules☆23Aug 1, 2024Updated 2 years ago
- ☆88Apr 8, 2026Updated 4 months ago
- A lightweight Command and Control (C2) framework built for offensive security research and red teaming (Post Exploitation).☆68Dec 17, 2025Updated 8 months ago
- Cobalt Strike BOF to obtain location data☆30Jul 4, 2026Updated last month
- Another FAFO project: Weaponizing MSI installers for fileless code execution☆54Aug 12, 2026Updated last week
- Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijac…☆157Jul 20, 2026Updated last month
- Thermal pocket printer - BLE protocol reverse engineering, Python CLI, and web GUI☆18May 4, 2026Updated 3 months ago
- A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Slee…☆95Jul 26, 2026Updated 3 weeks ago
- Generate DLL proxy/sideload projects. Automatically parses PE export tables and generates ready-to-compile project for red team engagemen…☆157Mar 8, 2026Updated 5 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Create local administrators with the SAMR API (lowest-level technique). Implemented in C#, Crystal, Python and Rust☆96Aug 17, 2026Updated last week
- A list of Cheatsheet compiled by CloudBreach Team☆50Jun 18, 2026Updated 2 months ago
- Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin res…☆88Jun 20, 2026Updated 2 months ago
- Polymorphic PE rewriter for Windows x64 , rewrites binaries into semantically identical but byte-different variants☆200Jun 6, 2026Updated 2 months ago
- MalwareScan is a lightweight and fast malware scanner written in Python. It supports both Windows and Linux platforms and provides an ope…☆13Jun 2, 2025Updated last year
- Rust rewrite of nanodump, a low-level LSASS memory dumping tool.☆16Feb 22, 2026Updated 6 months ago
- A stealthier approach to WMI-based command execution using Impacket without touching the disk.☆88Mar 15, 2026Updated 5 months ago
- PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping☆36May 12, 2026Updated 3 months ago
- A EDR bypassing shellcode loader framework for Windows 10 64bit, featuring ETW/AMSI patching, Tartarus Gate, process protection and more☆95Jun 24, 2026Updated last month
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Remote DLL Injection with Timer-based Shellcode Execution☆216Jul 18, 2025Updated last year
- VDM sig bypass and additional WinAPI stubs☆20Feb 16, 2026Updated 6 months ago
- Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)☆106Apr 4, 2026Updated 4 months ago
- KslDump — Why bring your own knife when Defender already left one in the kitchen?☆399Apr 13, 2026Updated 4 months ago
- BYOVD hunter to help prioritize windows drivers worth manual analysis☆132Aug 19, 2025Updated last year
- Active network shares enumeration tool.☆38Jul 17, 2026Updated last month
- In-memory BOF implementation of Silent Process Exit LSASS dump via RtlReportSilentProcessExit☆19Apr 14, 2026Updated 4 months ago