A collection of techniques, examples and a little bit of theory for manually obfuscating PowerShell scripts to achieve AV evasion, compiled for educational purposes. The contents of this repository are the result of personal research, including reading materials online and conducting trial-and-error attempts in labs and pentests.
☆1,195Jul 19, 2024Updated 2 years ago
Alternatives and similar repositories for PowerShell-Obfuscation-Bible
Users that are interested in PowerShell-Obfuscation-Bible are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A memory-based evasion technique which makes shellcode invisible from process start to end.☆1,201Oct 16, 2023Updated 2 years ago
- Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality…☆4,417May 21, 2025Updated last year
- This map lists the essential techniques to bypass anti-virus and EDR☆3,364Mar 28, 2025Updated last year
- Awesome EDR Bypass Resources For Ethical Hacking☆1,553Jan 26, 2026Updated 5 months ago
- Lifetime AMSI bypass☆681Sep 26, 2023Updated 2 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Dominate Active Directory with PowerShell.☆1,192Nov 28, 2025Updated 7 months ago
- An ADCS Exploitation Automation Tool Weaponizing Certipy and Coercer☆750May 19, 2023Updated 3 years ago
- The Hunt for Malicious Strings☆1,400May 13, 2025Updated last year
- Shellcode encryptor & obfuscator tool☆1,032Updated this week
- Automated DLL Sideloading Tool With EDR Evasion Capabilities☆507Dec 19, 2023Updated 2 years ago
- This repo contains some Amsi Bypass methods i found on different Blog Posts.☆2,185Nov 28, 2024Updated last year
- A tool which bypasses AMSI (AntiMalware Scan Interface) and PowerShell CLM (Constrained Language Mode) and gives you a FullLanguage Power…☆823Mar 28, 2025Updated last year
- Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes☆1,061Jun 20, 2023Updated 3 years ago
- C# obfuscator that bypass windows defender☆824Jun 4, 2023Updated 3 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- .NET assembly loader with patchless AMSI and ETW bypass☆386Apr 19, 2023Updated 3 years ago
- A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techni…☆1,402Oct 27, 2023Updated 2 years ago
- a tool to help operate in EDRs' blind spots☆772Dec 2, 2024Updated last year
- Revenant - A 3rd party agent for Havoc that demonstrates evasion techniques in the context of a C2 framework☆390Jul 30, 2024Updated last year
- Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird …☆804Jan 26, 2026Updated 5 months ago
- Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods☆1,476Aug 18, 2023Updated 2 years ago
- ☆722Mar 22, 2024Updated 2 years ago
- Killer is a super simple tool designed to bypass AV/EDR security tools using various evasive techniques and used by Patchwork group.☆846Jul 2, 2024Updated 2 years ago
- PoC module to demonstrate automated lateral movement with the Havoc C2 framework.☆313Dec 9, 2023Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Windows Local Privilege Escalation Cookbook☆1,356Feb 5, 2026Updated 5 months ago
- kill anti-malware protected processes ( BYOVD )☆983Jul 21, 2023Updated 3 years ago
- ☆2,318Nov 24, 2023Updated 2 years ago
- This repo contains C/C++ snippets that can be handy in specific offensive scenarios.☆769Jan 26, 2025Updated last year
- HVNC for Cobalt Strike☆1,336Dec 7, 2023Updated 2 years ago
- A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.☆3,477Jan 19, 2025Updated last year
- PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.☆609Jan 20, 2026Updated 6 months ago
- EDR Lab for Experimentation Purposes☆1,506Jun 10, 2026Updated last month
- Amsi Bypass payload that works on Windwos 11☆381Jul 30, 2023Updated 2 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Active Directory Auditing and Enumeration☆539Jun 12, 2026Updated last month
- Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8☆351Aug 29, 2024Updated last year
- A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file form…☆1,185Jun 10, 2024Updated 2 years ago
- Dump NTDS with golden certificates and UnPAC the hash☆648Mar 20, 2024Updated 2 years ago
- Simple & Powerful PowerShell Script Obfuscator☆593May 13, 2025Updated last year
- Lateral Movement Using DCOM and DLL Hijacking☆327Jun 18, 2023Updated 3 years ago
- Simulate the behavior of AV/EDR for malware development training.☆568Feb 15, 2024Updated 2 years ago