Compile-time AES string obfuscation for C++
☆110May 26, 2026Updated 2 months ago
Alternatives and similar repositories for sbox
Users that are interested in sbox are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- .NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on dis…☆41Jul 13, 2026Updated last month
- ☆33Jul 14, 2026Updated last month
- Intel 64/Windows low-level experiments☆108Jul 21, 2026Updated last month
- Hijacking the Windows network stack from the kernel :)☆46May 5, 2026Updated 3 months ago
- Windows User-Mode Shellcode Development Framework (WUMSDF)☆157Jul 15, 2026Updated last month
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- x64 PE bin2bin obfuscator which doesn't add a section to the binary☆317Updated this week
- Obfusk8: lightweight Obfuscation library based on C++17 / Header Only for windows binaries☆806Jun 25, 2026Updated last month
- .NET CLR-Stomping☆148May 20, 2026Updated 3 months ago
- Native C++ access to Active Directory over ADWS, no .NET, no WCF, no HTTP stack.☆82Mar 27, 2026Updated 4 months ago
- AD ACL Abuser for Havoc C2☆25Mar 30, 2026Updated 4 months ago
- out-of-tree LLVM 21+ pass plugin for policy-driven IR obfuscation.☆100Updated this week
- Moonwalk++: Simple POC Combining StackMoonwalking and Memory Encryption☆233Dec 17, 2025Updated 8 months ago
- A cross-platform C++ framework for building Windows shellcode☆176Apr 21, 2026Updated 4 months ago
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆50Jul 23, 2026Updated last month
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A compiled language for Windows position-independent x86-64 shellcode and Beacon Object Files.☆180Jun 28, 2026Updated last month
- Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advance…☆117Jun 30, 2026Updated last month
- A simple POC to show how to chain multiple callbacks via tail calls to artificially construct a call stack☆111May 25, 2026Updated 2 months ago
- arm64 linux position-independent shellcode framework☆31Dec 12, 2025Updated 8 months ago
- A POC tool for exploring dev-tunnels☆66May 5, 2026Updated 3 months ago
- Crystal Palace library for proxying Nt API calls via the Threadpool☆107Oct 18, 2025Updated 10 months ago
- Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.☆86Jun 15, 2026Updated 2 months ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 4 months ago
- A basic implementation of Patch Guard that I implemented, that includes integrity checks and other protection mechanisms I added.☆78Mar 29, 2025Updated last year
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A runtime for developing large-scale and complex PIC module.☆21Updated this week
- Async BOF that monitors USB device connect/disconnect events, reports device information and performs actions on connected USB storage vo…☆58Jul 23, 2026Updated last month
- test☆108Apr 25, 2026Updated 3 months ago
- tests to catch some sloppy hv impls☆34Mar 16, 2026Updated 5 months ago
- BingusLdr is a DLL loader built with Crystal Palace that uses a CET compatible stack spoofing technique.☆112Jul 14, 2026Updated last month
- KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.☆216Jul 8, 2026Updated last month
- Noradrenaline is a collection of high-performance post-exploitation shared libraries designed for native execution on macOS and Linux end…☆30Jul 6, 2026Updated last month
- Injecting code by recompiling shellcode into a ROP chain.☆146Apr 21, 2026Updated 4 months ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆119Dec 21, 2025Updated 8 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Async port/ping scanner BOF. Supports IP/port ranges, CIDR notation and hostnames.☆18Jul 23, 2026Updated last month
- BOF POC of the DSCourier project / invoking WinGet via COM☆90Apr 23, 2026Updated 4 months ago
- A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++☆263Jun 18, 2026Updated 2 months ago
- A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.☆143Jan 28, 2026Updated 6 months ago
- SysCaller: SDK for WindowsAPI via syscalls. Dynamic Resolution, Obfuscation, Multi-Language Bindings, & more!☆68Nov 17, 2025Updated 9 months ago
- DSCourier is a proof-of-concept that uses the WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries.☆210Jun 25, 2026Updated last month
- Polymorphic PE rewriter for Windows x64 , rewrites binaries into semantically identical but byte-different variants☆200Jun 6, 2026Updated 2 months ago