Polymorphic AV/AMSI bypass toolkit - Donut shellcode runner for offensive .NET/PE tools
☆36May 26, 2026Updated 2 months ago
Alternatives and similar repositories for killshot
Users that are interested in killshot are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Automated script for obfuscating, rebranding and renaming the Havoc C2 Framework to evade AV/EDR and C2 hunters.☆49Aug 13, 2025Updated 11 months ago
- Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification s…☆42Jun 4, 2026Updated last month
- A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.☆58Jul 20, 2026Updated 2 weeks ago
- Active Directory forensic framework☆16May 18, 2026Updated 2 months ago
- COM Windows Persistence Technique☆90Apr 27, 2026Updated 3 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advance…☆114Jun 30, 2026Updated last month
- Phantom is project created to perform loading and executing unmanaged code in memory within an IIS environment running in full‑trust mode…☆106Jun 5, 2026Updated last month
- Evasive loader for .NET Framework assemblies☆45May 14, 2026Updated 2 months ago
- Another BYOVD process killer. works on all EDR's. fully signed.☆288May 19, 2026Updated 2 months ago
- Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.☆67Mar 2, 2026Updated 5 months ago
- A C# PE loader for x64 and x86 PE files.☆56Mar 9, 2026Updated 4 months ago
- Collection of custom implementations about some WinAPI functions☆35Updated this week
- Async port/ping scanner BOF. Supports IP/port ranges, CIDR notation and hostnames.☆18Jul 23, 2026Updated last week
- Python3 tool to perform password spraying using RDP☆17Aug 14, 2023Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- ☆88Apr 8, 2026Updated 3 months ago
- A lightweight Command and Control (C2) framework built for offensive security research and red teaming (Post Exploitation).☆68Dec 17, 2025Updated 7 months ago
- Another FAFO project: Weaponizing MSI installers for fileless code execution☆34May 7, 2026Updated 2 months ago
- Cobalt Strike BOF to obtain location data☆29Jul 4, 2026Updated 3 weeks ago
- Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijac…☆136Jul 20, 2026Updated 2 weeks ago
- A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Slee…☆78Jul 26, 2026Updated last week
- Thermal pocket printer - BLE protocol reverse engineering, Python CLI, and web GUI☆15May 4, 2026Updated 2 months ago
- Create local administrators with the SAMR API (lowest-level technique). Implemented in C#, Crystal, Python and Rust☆95Mar 7, 2026Updated 4 months ago
- ☆36Jul 1, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A list of Cheatsheet compiled by CloudBreach Team☆50Jun 18, 2026Updated last month
- Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin res…☆87Jun 20, 2026Updated last month
- Polymorphic PE rewriter for Windows x64 , rewrites binaries into semantically identical but byte-different variants☆200Jun 6, 2026Updated last month
- MalwareScan is a lightweight and fast malware scanner written in Python. It supports both Windows and Linux platforms and provides an ope…☆13Jun 2, 2025Updated last year
- Rust rewrite of nanodump, a low-level LSASS memory dumping tool.☆16Feb 22, 2026Updated 5 months ago
- A stealthier approach to WMI-based command execution using Impacket without touching the disk.☆86Mar 15, 2026Updated 4 months ago
- PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping☆34May 12, 2026Updated 2 months ago
- A EDR bypassing shellcode loader framework for Windows 10 64bit, featuring ETW/AMSI patching, Tartarus Gate, process protection and more☆92Jun 24, 2026Updated last month
- Remote DLL Injection with Timer-based Shellcode Execution☆216Jul 18, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- VDM sig bypass and additional WinAPI stubs☆19Feb 16, 2026Updated 5 months ago
- Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)☆107Apr 4, 2026Updated 3 months ago
- KslDump — Why bring your own knife when Defender already left one in the kitchen?☆398Apr 13, 2026Updated 3 months ago
- Bypassing AVs and Sandboxes☆21Oct 9, 2025Updated 9 months ago
- BYOVD hunter to help prioritize windows drivers worth manual analysis☆131Aug 19, 2025Updated 11 months ago
- Active network shares enumeration tool.☆36Jul 17, 2026Updated 2 weeks ago
- In-memory BOF implementation of Silent Process Exit LSASS dump via RtlReportSilentProcessExit☆19Apr 14, 2026Updated 3 months ago