Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process hollowing. Built in Rust for speed. Includes CLI and TUI interfaces.
☆381Aug 7, 2026Updated last week
Alternatives and similar repositories for ghost
Users that are interested in ghost are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Sanctum is an experimental proof-of-concept EDR, designed to detect modern malware techniques, above and beyond the capabilities of antiv…☆568Mar 24, 2026Updated 4 months ago
- ☆114Jul 10, 2026Updated last month
- Context-aware Nmap reconnaissance framework with traffic intelligence and AD awareness☆26Feb 4, 2026Updated 6 months ago
- COM Windows Persistence Technique☆90Apr 27, 2026Updated 3 months ago
- .NET tool used to enrich RPC telemetry☆103Jan 24, 2026Updated 6 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Overview of MS Defender☆156Feb 20, 2026Updated 5 months ago
- VDM sig bypass and additional WinAPI stubs☆19Feb 16, 2026Updated 5 months ago
- Async BOF that monitors USB device connect/disconnect events, reports device information and performs actions on connected USB storage vo…☆57Jul 23, 2026Updated 3 weeks ago
- TheDarkMark is a C2 framework designed to be fast and parallel.☆24Jul 21, 2026Updated 3 weeks ago
- ☆15Jan 15, 2026Updated 7 months ago
- Red Team Coin for crypto-mining operations.☆25Mar 1, 2026Updated 5 months ago
- EDR-Redir : a tool used to redirect the EDR's folder to another location.☆239May 23, 2026Updated 2 months ago
- proper ntdll .text section unhooking via native api. unlike other unhookers this doesnt leave 2 ntdlls loaded. x86/x64/wow64 supported.☆55Dec 9, 2025Updated 8 months ago
- ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.☆33Apr 12, 2026Updated 4 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- BOF to terminate a process via PID as argument☆28Sep 7, 2025Updated 11 months ago
- template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.☆107Jan 10, 2026Updated 7 months ago
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆27May 21, 2026Updated 2 months ago
- Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.☆87Jun 15, 2026Updated 2 months ago
- Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !☆43Mar 24, 2026Updated 4 months ago
- Evade behavioral analysis by executing malicious code within trusted Microsoft call stacks, patchless hooking library IAT/EAT.☆149Dec 8, 2025Updated 8 months ago
- takes shellcode bad-bytes and banishes them, returning cleaned shellcode with preserved functionalities☆63Mar 1, 2026Updated 5 months ago
- Pipeline for creating shellcode from a nostd rust project.☆27Jul 11, 2024Updated 2 years ago
- Stealthy x64 thread manipulation library for calling functions inside target processes without creating remote threads or installing hook…☆59Oct 10, 2025Updated 10 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- AI-powered Windows Event Log analyzer that learns from your feedback. Uses Claude AI with RAG to detect suspicious activity, improve ac…☆37Dec 18, 2025Updated 7 months ago
- AI-driven automated threat analysis pipeline that routes files, URLs, IPs, domains, or images through specialized security analyzers and …☆16Mar 9, 2026Updated 5 months ago
- Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. Implemented in C#, C++, Crystal, P…☆154Feb 17, 2026Updated 5 months ago
- ☆17Oct 2, 2024Updated last year
- This C# tool sprays for admin access over the entire domain☆90Dec 7, 2025Updated 8 months ago
- Lnk crafting and research tools☆186Mar 4, 2026Updated 5 months ago
- IronPE is a Windows PE manual loader written in Rust for both x86 and x64 PE files.☆124Mar 10, 2026Updated 5 months ago
- Programa para encriptar y desencriptar archivos utilizando una clave de cifrado.☆19Mar 19, 2026Updated 4 months ago
- A high-fidelity x86_64 polymorphic mutation engine focused on instruction-level fragmentation and context preservation.☆112Jan 18, 2026Updated 6 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but fo…☆175Jun 19, 2026Updated last month
- Code execution/injection technique using DLL PEB module structure manipulation☆289Jun 4, 2025Updated last year
- AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64☆553Mar 7, 2026Updated 5 months ago
- PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via …☆167Jan 25, 2026Updated 6 months ago
- BlackRecon is an automated reconnaissance tool designed for ethical hacking and security assessments. It enumerates subdomains, resolves …☆23Apr 27, 2025Updated last year
- Dynamic shellcode loader with sophisticated evasion capabilities☆346Oct 1, 2025Updated 10 months ago
- Toolkit de binarios para auditar entornos Active Directory☆15Apr 29, 2026Updated 3 months ago