Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process hollowing. Built in Rust for speed. Includes CLI and TUI interfaces.
☆391Aug 7, 2026Updated last month
Alternatives and similar repositories for ghost
Users that are interested in ghost are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Sanctum is an experimental proof-of-concept EDR, designed to detect modern malware techniques, above and beyond the capabilities of antiv…☆567Mar 24, 2026Updated 6 months ago
- Context-aware Nmap reconnaissance framework with traffic intelligence and AD awareness☆26Feb 4, 2026Updated 7 months ago
- .NET tool used to enrich RPC telemetry☆101Jan 24, 2026Updated 8 months ago
- VDM sig bypass and additional WinAPI stubs☆19Feb 16, 2026Updated 7 months ago
- ☆15Jan 15, 2026Updated 8 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- COM Windows Persistence Technique☆89Apr 27, 2026Updated 5 months ago
- Overview of MS Defender☆165Feb 20, 2026Updated 7 months ago
- proper ntdll .text section unhooking via native api. unlike other unhookers this doesnt leave 2 ntdlls loaded. x86/x64/wow64 supported.☆56Dec 9, 2025Updated 9 months ago
- BOF to terminate a process via PID as argument☆27Sep 7, 2025Updated last year
- Async BOF that monitors USB device connect/disconnect events, reports device information and performs actions on connected USB storage vo…☆57Jul 23, 2026Updated 2 months ago
- EDR-Redir : a tool used to redirect the EDR's folder to another location.☆244May 23, 2026Updated 4 months ago
- TheDarkMark is a C2 framework designed to be fast and parallel.☆24Jul 21, 2026Updated 2 months ago
- takes shellcode bad-bytes and banishes them, returning cleaned shellcode with preserved functionalities☆62Mar 1, 2026Updated 6 months ago
- Pipeline for creating shellcode from a nostd rust project.☆27Jul 11, 2024Updated 2 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Stealthy x64 thread manipulation library for calling functions inside target processes without creating remote threads or installing hook…☆59Oct 10, 2025Updated 11 months ago
- Red Team Coin for crypto-mining operations.☆25Mar 1, 2026Updated 6 months ago
- template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.☆106Jan 10, 2026Updated 8 months ago
- ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.☆36Apr 12, 2026Updated 5 months ago
- AI-powered Windows Event Log analyzer that learns from your feedback. Uses Claude AI with RAG to detect suspicious activity, improve ac…☆38Dec 18, 2025Updated 9 months ago
- Evade behavioral analysis by executing malicious code within trusted Microsoft call stacks, patchless hooking library IAT/EAT.☆148Dec 8, 2025Updated 9 months ago
- ☆17Oct 2, 2024Updated last year
- Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.☆90Jun 15, 2026Updated 3 months ago
- Code execution/injection technique using DLL PEB module structure manipulation☆288Jun 4, 2025Updated last year
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !☆44Mar 24, 2026Updated 6 months ago
- Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. In C#, C++, Crystal, Python, Rust,…☆155Aug 31, 2026Updated 3 weeks ago
- Lnk crafting and research tools☆185Mar 4, 2026Updated 6 months ago
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆29May 21, 2026Updated 4 months ago
- Serving payloads only to allowed processes using Windows projected file system feature☆25Feb 7, 2026Updated 7 months ago
- AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64☆565Mar 7, 2026Updated 6 months ago
- A Proof-of-Concept bootkit and UEFI boot application inspired by Petya ransomware, written in Assembly, C, and C++☆276Sep 11, 2026Updated 2 weeks ago
- This C# tool sprays for admin access over the entire domain☆90Dec 7, 2025Updated 9 months ago
- IronPE is a Windows PE manual loader written in Rust for both x86 and x64 PE files.☆124Mar 10, 2026Updated 6 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but fo…☆175Jun 19, 2026Updated 3 months ago
- Dynamic shellcode loader with sophisticated evasion capabilities☆344Oct 1, 2025Updated 11 months ago
- use python on windows with full submodule support without installation☆30Jan 23, 2025Updated last year
- A Rust template for writing Beacon Object Files (BOFs)☆133Feb 11, 2026Updated 7 months ago
- Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when a…☆97Jul 7, 2025Updated last year
- A high-fidelity x86_64 polymorphic mutation engine focused on instruction-level fragmentation and context preservation.☆112Jan 18, 2026Updated 8 months ago
- Bora Jogar?☆15Aug 30, 2026Updated 3 weeks ago