Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process hollowing. Built in Rust for speed. Includes CLI and TUI interfaces.
☆392Aug 7, 2026Updated last month
Alternatives and similar repositories for ghost
Users that are interested in ghost are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Sanctum is an experimental proof-of-concept EDR, designed to detect modern malware techniques, above and beyond the capabilities of antiv…☆568Mar 24, 2026Updated 5 months ago
- Context-aware Nmap reconnaissance framework with traffic intelligence and AD awareness☆26Feb 4, 2026Updated 7 months ago
- COM Windows Persistence Technique☆90Apr 27, 2026Updated 4 months ago
- .NET tool used to enrich RPC telemetry☆102Jan 24, 2026Updated 7 months ago
- Overview of MS Defender☆162Feb 20, 2026Updated 6 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- VDM sig bypass and additional WinAPI stubs☆20Feb 16, 2026Updated 6 months ago
- Async BOF that monitors USB device connect/disconnect events, reports device information and performs actions on connected USB storage vo…☆58Jul 23, 2026Updated last month
- TheDarkMark is a C2 framework designed to be fast and parallel.☆24Jul 21, 2026Updated last month
- ☆15Jan 15, 2026Updated 7 months ago
- Red Team Coin for crypto-mining operations.☆25Mar 1, 2026Updated 6 months ago
- EDR-Redir : a tool used to redirect the EDR's folder to another location.☆242May 23, 2026Updated 3 months ago
- ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.☆33Apr 12, 2026Updated 4 months ago
- proper ntdll .text section unhooking via native api. unlike other unhookers this doesnt leave 2 ntdlls loaded. x86/x64/wow64 supported.☆56Dec 9, 2025Updated 8 months ago
- BOF to terminate a process via PID as argument☆28Sep 7, 2025Updated last year
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.☆107Jan 10, 2026Updated 7 months ago
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆27May 21, 2026Updated 3 months ago
- Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.☆89Jun 15, 2026Updated 2 months ago
- Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !☆44Mar 24, 2026Updated 5 months ago
- Evade behavioral analysis by executing malicious code within trusted Microsoft call stacks, patchless hooking library IAT/EAT.☆149Dec 8, 2025Updated 8 months ago
- takes shellcode bad-bytes and banishes them, returning cleaned shellcode with preserved functionalities☆63Mar 1, 2026Updated 6 months ago
- Pipeline for creating shellcode from a nostd rust project.☆27Jul 11, 2024Updated 2 years ago
- Stealthy x64 thread manipulation library for calling functions inside target processes without creating remote threads or installing hook…☆59Oct 10, 2025Updated 10 months ago
- AI-powered Windows Event Log analyzer that learns from your feedback. Uses Claude AI with RAG to detect suspicious activity, improve ac…☆37Dec 18, 2025Updated 8 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. In C#, C++, Crystal, Python, Rust,…☆156Aug 31, 2026Updated last week
- ☆17Oct 2, 2024Updated last year
- This C# tool sprays for admin access over the entire domain☆90Dec 7, 2025Updated 9 months ago
- Lnk crafting and research tools☆186Mar 4, 2026Updated 6 months ago
- IronPE is a Windows PE manual loader written in Rust for both x86 and x64 PE files.☆124Mar 10, 2026Updated 5 months ago
- A high-fidelity x86_64 polymorphic mutation engine focused on instruction-level fragmentation and context preservation.☆111Jan 18, 2026Updated 7 months ago
- Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but fo…☆176Jun 19, 2026Updated 2 months ago
- Code execution/injection technique using DLL PEB module structure manipulation☆287Jun 4, 2025Updated last year
- PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via …☆167Jan 25, 2026Updated 7 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Dynamic shellcode loader with sophisticated evasion capabilities☆346Oct 1, 2025Updated 11 months ago
- Serving payloads only to allowed processes using Windows projected file system feature☆25Feb 7, 2026Updated 7 months ago
- A Proof-of-Concept bootkit and UEFI boot application inspired by Petya ransomware, written in Assembly, C, and C++☆271Updated this week
- Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techn…☆59Jul 5, 2026Updated 2 months ago
- 🛡️ Open-source binary protection toolkit for Windows PE. Nanomite, VM protection, anti-debug, and more.☆61Feb 8, 2026Updated 6 months ago
- AI-driven automated threat analysis pipeline that routes files, URLs, IPs, domains, or images through specialized security analyzers and …☆20Mar 9, 2026Updated 5 months ago
- M365 Conditional Access Policy Bypass OST (Offensive Tooling)☆45Apr 22, 2026Updated 4 months ago