A new technique that can be used to bypass memory scanners. This can be useful in hiding problematic code (such as reflective loaders implemented by C2 beacons) or other problematic executables that will be flagged by the antimalware programs(such as mimikatz).
☆359Oct 7, 2024Updated last year
Alternatives and similar repositories for Voidmaw
Users that are interested in Voidmaw are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Sleep obfuscation☆275Dec 13, 2024Updated last year
- Cobaltstrike Reflective Loader with Synthetic Stackframe☆193Jan 17, 2026Updated 8 months ago
- BOF with Synthetic Stackframe☆263Oct 30, 2025Updated 10 months ago
- BOF that finds all the Nt* system call stubs within NTDLL and overwrites with clean syscall stubs (user land hook evasion)☆219Feb 6, 2025Updated last year
- A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfve…☆598Jun 12, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- COM ViewLogger — new malware keylogging technique☆409Jan 6, 2025Updated last year
- Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR …☆312Jul 31, 2024Updated 2 years ago
- Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird …☆810Jan 26, 2026Updated 7 months ago
- NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-bui…☆241Feb 12, 2025Updated last year
- early cascade injection PoC based on Outflanks blog post☆240Nov 7, 2024Updated last year
- "Service-less" driver loading☆191Nov 28, 2024Updated last year
- Code execution/injection technique using DLL PEB module structure manipulation☆287Jun 4, 2025Updated last year
- Two new offensive techniques using Windows Fibers: PoisonFiber (The first remote enumeration & Fiber injection capability POC tool) Phan…☆285Sep 18, 2024Updated 2 years ago
- DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely☆396Dec 13, 2024Updated last year
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution☆193Nov 27, 2024Updated last year
- Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.☆325Apr 12, 2024Updated 2 years ago
- Collect Windows telemetry for Maldev☆508Aug 14, 2026Updated last month
- Shellcode loader☆104Nov 24, 2024Updated last year
- Evasive shellcode loader☆400Oct 17, 2024Updated last year
- Playing around with Thread Context Hijacking. Building more evasive primitives to use as alternative for existing process injection techn…☆208Jun 17, 2025Updated last year
- Windows User-Mode Shellcode Development Framework (WUMSDF)☆159Jul 15, 2026Updated 2 months ago
- .NET assembly loader with patchless AMSI and ETW bypass☆388Apr 19, 2023Updated 3 years ago
- Bypass Credential Guard by patching WDigest.dll using only NTAPI functions☆269Apr 8, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- early cascade injection PoC based on Outflanks blog post, in rust☆63Nov 8, 2024Updated last year
- Stage 0☆170Dec 18, 2024Updated last year
- Generic PE loader for fast prototyping evasion techniques☆246Jul 2, 2024Updated 2 years ago
- Port of Cobalt Strike's Process Inject Kit☆193Dec 1, 2024Updated last year
- C2 Agent fully PIC for Mythic with advanced evasion capabilities, dotnet/powershell/shellcode/bof memory executions, lateral moviments, p…☆216Dec 30, 2025Updated 8 months ago
- A Mythic Agent written in PIC C.☆216Feb 4, 2025Updated last year
- Metamorphic cross-compilation of C++ & C-code to PIC, BOF & EXE.☆647Feb 2, 2026Updated 7 months ago
- Shadow Dumper is a powerful tool used to dump LSASS memory, often needed in penetration testing and red teaming. It uses multiple advance…☆588May 22, 2025Updated last year
- Identify common EDR processes, directories, and services. Simple BOF of Invoke-EDRChecker.☆135Oct 4, 2024Updated last year
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Run native PE or .NET executables entirely in-memory. Build the loader as an .exe or .dll—DllMain is Cobalt Strike UDRL-compatible☆277Jun 18, 2025Updated last year
- Reaping treasures from strings in remote processes memory☆287Feb 8, 2025Updated last year
- Mirage is a PoC memory evasion technique that relies on a vulnerable VBS enclave to hide shellcode within VTL1.☆108Feb 25, 2025Updated last year
- A Powershell AMSI Bypass technique via Vectored Exception Handler (VEH). This technique does not perform assembly instruction patching, f…☆173May 30, 2024Updated 2 years ago
- A C++ proof of concept demonstrating the exploitation of Windows Protected Process Light (PPL) by leveraging COM-to-.NET redirection and …☆335Mar 6, 2025Updated last year
- find dll base addresses without PEB WALK☆169Jul 13, 2025Updated last year
- A simple POC to show how to chain multiple callbacks via tail calls to artificially construct a call stack☆111May 25, 2026Updated 3 months ago