Polymorphic AV/AMSI bypass toolkit - Donut shellcode runner for offensive .NET/PE tools
☆36May 26, 2026Updated 4 months ago
Alternatives and similar repositories for killshot
Users that are interested in killshot are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Automated script for obfuscating, rebranding and renaming the Havoc C2 Framework to evade AV/EDR and C2 hunters.☆49Aug 13, 2025Updated last year
- Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification s…☆42Jun 4, 2026Updated 3 months ago
- A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.☆63Jul 20, 2026Updated 2 months ago
- Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.☆65Mar 2, 2026Updated 7 months ago
- A C# PE loader for x64 and x86 PE files.☆57Mar 9, 2026Updated 6 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- COM Windows Persistence Technique☆89Apr 27, 2026Updated 5 months ago
- Another BYOVD process killer. works on all EDR's. fully signed.☆291May 19, 2026Updated 4 months ago
- Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advance…☆119Sep 17, 2026Updated 2 weeks ago
- Python3 tool to perform password spraying using RDP☆17Aug 14, 2023Updated 3 years ago
- Phantom is project created to perform loading and executing unmanaged code in memory within an IIS environment running in full‑trust mode…☆107Jun 5, 2026Updated 3 months ago
- Evasive loader for .NET Framework assemblies☆51May 14, 2026Updated 4 months ago
- Active Directory forensic framework☆16May 18, 2026Updated 4 months ago
- Collection of custom implementations about some WinAPI functions☆38Jul 30, 2026Updated 2 months ago
- Cobalt Strike BOF to obtain location data☆29Jul 4, 2026Updated 2 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆89Sep 3, 2026Updated last month
- Async port/ping scanner BOF. Supports IP/port ranges, CIDR notation and hostnames.☆17Jul 23, 2026Updated 2 months ago
- A lightweight Command and Control (C2) framework built for offensive security research and red teaming (Post Exploitation).☆67Dec 17, 2025Updated 9 months ago
- Generate DLL proxy/sideload projects. Automatically parses PE export tables and generates ready-to-compile project for red team engagemen…☆170Sep 13, 2026Updated 2 weeks ago
- Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijac…☆161Jul 20, 2026Updated 2 months ago
- MalwareScan is a lightweight and fast malware scanner written in Python. It supports both Windows and Linux platforms and provides an ope…☆13Jun 2, 2025Updated last year
- Rust rewrite of nanodump, a low-level LSASS memory dumping tool.☆16Feb 22, 2026Updated 7 months ago
- A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Slee…☆111Jul 26, 2026Updated 2 months ago
- Create local administrators in Windows using the SAMR API. In C#, Crystal, Python, Rust, Golang, Nim and Deno (Javascript)☆97Aug 31, 2026Updated last month
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Another FAFO project: Weaponizing MSI installers for fileless code execution☆58Aug 12, 2026Updated last month
- Remote DLL Injection with Timer-based Shellcode Execution☆215Jul 18, 2025Updated last year
- VDM sig bypass and additional WinAPI stubs☆20Feb 16, 2026Updated 7 months ago
- Polymorphic PE rewriter for Windows x64 , rewrites binaries into semantically identical but byte-different variants☆200Jun 6, 2026Updated 3 months ago
- PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping☆37May 12, 2026Updated 4 months ago
- A list of Cheatsheet compiled by CloudBreach Team☆53Jun 18, 2026Updated 3 months ago
- Morpheus is an lsass stealer that extracts lsass.exe in RAM and exfiltrates it via forged and crypted NTP packets. For authorized testin…☆169Jun 19, 2025Updated last year
- Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin res…☆88Jun 20, 2026Updated 3 months ago
- Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browser…☆261May 18, 2026Updated 4 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Advanced OPSEC fork of Donut. Features a Custom in-memory CLR Host, Tail-Jump ETW bypasses, and zero-patch AMSI evasion for stealthy shel…☆74Jun 24, 2026Updated 3 months ago
- The samples referenced in my book, Evasive Malware (No starch Press)☆61Feb 20, 2026Updated 7 months ago
- A stealthier approach to WMI-based command execution using Impacket without touching the disk.☆86Mar 15, 2026Updated 6 months ago
- Usermode Rootkit.☆60Apr 17, 2026Updated 5 months ago
- KslDump — Why bring your own knife when Defender already left one in the kitchen?☆415Apr 13, 2026Updated 5 months ago
- ☆70Jul 12, 2026Updated 2 months ago
- BYOVD hunter to help prioritize windows drivers worth manual analysis☆133Aug 19, 2025Updated last year