Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process hollowing. Built in Rust for speed. Includes CLI and TUI interfaces.
☆380Dec 15, 2025Updated 7 months ago
Alternatives and similar repositories for ghost
Users that are interested in ghost are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Sanctum is an experimental proof-of-concept EDR, designed to detect modern malware techniques, above and beyond the capabilities of antiv…☆567Mar 24, 2026Updated 4 months ago
- Context-aware Nmap reconnaissance framework with traffic intelligence and AD awareness☆26Feb 4, 2026Updated 5 months ago
- COM Windows Persistence Technique☆90Apr 27, 2026Updated 2 months ago
- .NET tool used to enrich RPC telemetry☆103Jan 24, 2026Updated 6 months ago
- Overview of MS Defender☆155Feb 20, 2026Updated 5 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- VDM sig bypass and additional WinAPI stubs☆19Feb 16, 2026Updated 5 months ago
- Async BOF that monitors USB device connect/disconnect events, reports device information and performs actions on connected USB storage vo…☆57Updated this week
- TheDarkMark is a C2 framework designed to be fast and parallel.☆24Updated this week
- ☆15Jan 15, 2026Updated 6 months ago
- Red Team Coin for crypto-mining operations.☆26Mar 1, 2026Updated 4 months ago
- EDR-Redir : a tool used to redirect the EDR's folder to another location.☆237May 23, 2026Updated 2 months ago
- proper ntdll .text section unhooking via native api. unlike other unhookers this doesnt leave 2 ntdlls loaded. x86/x64/wow64 supported.☆54Dec 9, 2025Updated 7 months ago
- ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.☆33Apr 12, 2026Updated 3 months ago
- BOF to terminate a process via PID as argument☆28Sep 7, 2025Updated 10 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.☆107Jan 10, 2026Updated 6 months ago
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆27May 21, 2026Updated 2 months ago
- Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.☆85Jun 15, 2026Updated last month
- Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !☆43Mar 24, 2026Updated 4 months ago
- Evade behavioral analysis by executing malicious code within trusted Microsoft call stacks, patchless hooking library IAT/EAT.☆146Dec 8, 2025Updated 7 months ago
- takes shellcode bad-bytes and banishes them, returning cleaned shellcode with preserved functionalities☆63Mar 1, 2026Updated 4 months ago
- Pipeline for creating shellcode from a nostd rust project.☆27Jul 11, 2024Updated 2 years ago
- Stealthy x64 thread manipulation library for calling functions inside target processes without creating remote threads or installing hook…☆59Oct 10, 2025Updated 9 months ago
- AI-powered Windows Event Log analyzer that learns from your feedback. Uses Claude AI with RAG to detect suspicious activity, improve ac…☆37Dec 18, 2025Updated 7 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- AI-driven automated threat analysis pipeline that routes files, URLs, IPs, domains, or images through specialized security analyzers and …☆16Mar 9, 2026Updated 4 months ago
- Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. Implemented in C#, C++, Crystal, P…☆154Feb 17, 2026Updated 5 months ago
- ☆17Oct 2, 2024Updated last year
- This C# tool sprays for admin access over the entire domain☆90Dec 7, 2025Updated 7 months ago
- Lnk crafting and research tools☆183Mar 4, 2026Updated 4 months ago
- IronPE is a Windows PE manual loader written in Rust for both x86 and x64 PE files.☆123Mar 10, 2026Updated 4 months ago
- A high-fidelity x86_64 polymorphic mutation engine focused on instruction-level fragmentation and context preservation.☆112Jan 18, 2026Updated 6 months ago
- Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but fo…☆174Jun 19, 2026Updated last month
- Code execution/injection technique using DLL PEB module structure manipulation☆287Jun 4, 2025Updated last year
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via …☆166Jan 25, 2026Updated 5 months ago
- AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64☆543Mar 7, 2026Updated 4 months ago
- Dynamic shellcode loader with sophisticated evasion capabilities☆342Oct 1, 2025Updated 9 months ago
- Serving payloads only to allowed processes using Windows projected file system feature☆25Feb 7, 2026Updated 5 months ago
- A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++☆258Jun 18, 2026Updated last month
- Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techn…☆55Jul 5, 2026Updated 2 weeks ago
- 🛡️ Open-source binary protection toolkit for Windows PE. Nanomite, VM protection, anti-debug, and more.☆59Feb 8, 2026Updated 5 months ago