wabzsy / gonut
Generator of https://github.com/TheWover/donut in pure Go. supports compression, AMSI/WLDP/ETW bypass, etc.
☆51Updated last year
Alternatives and similar repositories for gonut:
Users that are interested in gonut are comparing it to the libraries listed below
- Use the Netlogon Remote Protocol (MS-NRPC) to dump the target hash.☆46Updated last month
- Repository of scripts from my blog post on bypassing the YARA rule Windows_Trojan_CobaltStrike_f0b627fc by generating alternative shellco…☆35Updated 5 months ago
- Self Cleanup in post-ex job☆50Updated 6 months ago
- ELF Beacon Object File (BOF) Template☆48Updated 4 months ago
- Go implementation of the self-deletion of an running executable from disk☆106Updated last year
- A Simple PoC☆20Updated 10 months ago
- Silently Install Chrome Extension For Persistence☆49Updated 8 months ago
- 🔎🪲 Malleable C2 profiles parser and assembler written in golang☆64Updated 10 months ago
- Help red teams find opsec processes during engagements☆36Updated 3 months ago
- Beacon Object File to delete token privileges and lower the integrity level to untrusted for a specified process☆42Updated 2 years ago
- Golang implementation of @CCob's C# ThreadlessInject☆32Updated 10 months ago
- Evasive loader to bypass static detection☆57Updated last year
- ☆47Updated 11 months ago
- A BOF/COFF loader implemented in Go and CGO.☆17Updated last year
- load assembly executable file in memory☆40Updated last year
- Alternative Shellcode Execution Via Callbacks Rewrite In C#☆88Updated last year
- CLIPBRDWNDCLASS process injection technique(BOF) - execute beacon shellcode in callback☆68Updated 2 years ago
- Efficient RAT signature locator for bypassing AV/EDR, supporting static scanning and memory scanning.☆34Updated 5 months ago
- A Cobalt Strike memory evasion loader for redteamers☆98Updated 2 years ago
- ASPX ShellCode Loader☆49Updated last year
- Beacon Object File implementation of pwn1sher's KillDefender☆66Updated 2 years ago
- ReturnGate, just like HellsGate.☆66Updated 2 years ago
- Simple LSASS Dumper created using C++ as an alternative to using Mimikatz memory dumper☆54Updated 11 months ago
- A wrapper of ldap_shell.py module which in ntlmrelayx☆62Updated 2 years ago
- ☆79Updated last year
- ☆40Updated last year
- Golang implementation of Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll;☆32Updated 3 years ago
- Golang evasion tool, execute-assembly .Net file☆97Updated 2 years ago
- CVE-2024-40711-exp☆39Updated 5 months ago
- Extracts TEXT section of a PE, ELF, or Mach-O executable to shellcode☆103Updated last year