wabzsy / gonut
Generator of https://github.com/TheWover/donut in pure Go. supports compression, AMSI/WLDP/ETW bypass, etc.
☆56Updated last year
Alternatives and similar repositories for gonut
Users that are interested in gonut are comparing it to the libraries listed below
Sorting:
- Self Cleanup in post-ex job☆55Updated 8 months ago
- load assembly executable file in memory☆41Updated last year
- more conveniently Visual-Studio-BOF-template☆64Updated last year
- CLIPBRDWNDCLASS process injection technique(BOF) - execute beacon shellcode in callback☆68Updated 2 years ago
- 🔎🪲 Malleable C2 profiles parser and assembler written in golang☆65Updated last year
- Alternative Shellcode Execution Via Callbacks Rewrite In C#☆88Updated 2 years ago
- Evasive loader to bypass static detection☆60Updated last year
- Efficient RAT signature locator for bypassing AV/EDR, supporting static scanning and memory scanning.☆42Updated 6 months ago
- Its a coff loader ported to go( Modified by TimWhite )☆26Updated last year
- A Simple PoC☆21Updated 11 months ago
- AdaptixFramework Extension Kit☆76Updated last week
- Beacon Object File implementation of pwn1sher's KillDefender☆66Updated 2 years ago
- Extracts TEXT section of a PE, ELF, or Mach-O executable to shellcode☆103Updated 2 years ago
- frida based script which automates the process of discovering and exploiting DLL Hijacks in target binaries. The discovered binaries can …☆51Updated 2 years ago
- A BOF/COFF loader implemented in Go and CGO.☆22Updated last year
- Go implementation of the self-deletion of an running executable from disk☆108Updated last year
- MSSQL CLR for pentest.☆53Updated last year
- Silently Install Chrome Extension For Persistence☆51Updated 9 months ago
- Help red teams find opsec processes during engagements☆40Updated 5 months ago
- ☆40Updated last year
- Golang evasion tool, execute-assembly .Net file☆97Updated 3 years ago
- ☆47Updated last year
- Golang implementation of @CCob's C# ThreadlessInject☆32Updated last year
- ReturnGate, just like HellsGate.☆66Updated 2 years ago
- Repository of scripts from my blog post on bypassing the YARA rule Windows_Trojan_CobaltStrike_f0b627fc by generating alternative shellco…☆39Updated 6 months ago
- vehsyscall:a syscall project that may bypass EDR☆56Updated last year
- Beacon compiled using clang☆66Updated 2 years ago
- kill AV/EDR☆22Updated last year
- A Cobalt Strike memory evasion loader for redteamers☆99Updated 2 years ago
- A wrapper of ldap_shell.py module which in ntlmrelayx☆62Updated 2 years ago