Using Just In Time (JIT) instruction decryption, this shellcode loader ensures that only the currently executing instruction is visible in memory.
☆68Apr 2, 2025Updated last year
Alternatives and similar repositories for kong-loader
Users that are interested in kong-loader are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Boilerplate to develop raw and truly Position Independent Code (PIC).☆117Jan 20, 2025Updated last year
- A truly Position Independent Code (PIC) NimPlant C2 beacon written in C, without reflective loading.☆67Feb 11, 2025Updated last year
- ☆88Feb 12, 2026Updated 7 months ago
- Mirage is a PoC memory evasion technique that relies on a vulnerable VBS enclave to hide shellcode within VTL1.☆108Feb 25, 2025Updated last year
- Things i do because i saw it on twitter on a weekend☆56Jul 20, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Dynamically resolve API function addresses at runtime in a secure manner.☆74Nov 11, 2025Updated 10 months ago
- PIC shellcode (C/C++) development toolkit designed for malware developers.☆134Dec 23, 2025Updated 9 months ago
- A Proof of Concept demonstrating CET-compliant callstack spoofing in Rust. It leverages Windows Thread Pool and Enum Callback trampolinin…☆62Jul 12, 2026Updated 2 months ago
- C2 Agent fully PIC for Mythic with advanced evasion capabilities, dotnet/powershell/shellcode/bof memory executions, lateral moviments, p…☆216Dec 30, 2025Updated 8 months ago
- Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.☆46Aug 5, 2025Updated last year
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆101Jan 2, 2026Updated 8 months ago
- Example of call stack spoofing trough the construction of syntetic frames and stack manipulation☆41Jan 17, 2026Updated 8 months ago
- A sleepmask based on Ekko that preserves unwind data at sleep time.☆55Mar 30, 2026Updated 5 months ago
- An NTP channel for Beacons, implemented using Cobalt Strike’s External C2 framework.☆34Oct 6, 2025Updated 11 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Clean Indirect Syscalls with Hook Evasion & Return Address Spoofing.☆101Apr 30, 2026Updated 4 months ago
- Shellcode loader☆104Nov 24, 2024Updated last year
- ☆37Nov 8, 2024Updated last year
- ☆211Nov 28, 2023Updated 2 years ago
- A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike☆243Apr 11, 2026Updated 5 months ago
- BOF with Synthetic Stackframe☆265Oct 30, 2025Updated 10 months ago
- A Crystal Palace shared library to resolve & perform syscalls☆65Oct 29, 2025Updated 10 months ago
- BingusLdr is a DLL loader built with Crystal Palace that uses a CET compatible stack spoofing technique.☆114Jul 14, 2026Updated 2 months ago
- Metamorphic cross-compilation of C++ & C-code to PIC, BOF & EXE.☆650Feb 2, 2026Updated 7 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- open source implementation of the UDC2 spec used in Cobalt Strike☆59Jul 4, 2026Updated 2 months ago
- ForsHops☆58Mar 25, 2025Updated last year
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 4 months ago
- An example reference design for a proposed BOF PE☆246Jan 23, 2026Updated 8 months ago
- Shellcode injection using the Windows Debugging API☆181Jan 4, 2026Updated 8 months ago
- Waiting Thread Hijacking - injection by overwriting the return address of a waiting thread☆266Aug 31, 2025Updated last year
- Use the Netlogon Remote Protocol (MS-NRPC) to dump the target hash.☆61Feb 25, 2025Updated last year
- A Mythic Agent written in PIC C.☆216Feb 4, 2025Updated last year
- Rust template/library for implementing your own COFF loader☆71Jan 27, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Cobaltstrike Reflective Loader with Synthetic Stackframe☆192Jan 17, 2026Updated 8 months ago
- A BOF that's a BOF Loader and more☆212Apr 6, 2026Updated 5 months ago
- ⚡ SheetStrike - Weaponize Excel files for red team operations. Inject stealthy tracking pixels and NTLMv2 hash capture payloads into XLSX…☆22Dec 23, 2025Updated 9 months ago
- open source port/reimplementation of the Cobalt Strike BOF Loader as is☆73Mar 8, 2026Updated 6 months ago
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.☆55Mar 30, 2026Updated 5 months ago
- ForsHops☆156Mar 25, 2025Updated last year
- ☆34Mar 26, 2026Updated 5 months ago