Use of in-memory string scans to outsmart reverse engineers
☆20Nov 20, 2024Updated last year
Alternatives and similar repositories for Memory-Mirage-Anti-Debugging-
Users that are interested in Memory-Mirage-Anti-Debugging- are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Shadow Rebirth - An Aggressive Outbreak Anti-Debugging Technique☆21Dec 3, 2024Updated last year
- Anti-Debugging (Self-Debugging)☆17Sep 6, 2025Updated 11 months ago
- Alternative Read and Write primitives using Rtl* functions the unintended way.☆79Aug 25, 2025Updated 11 months ago
- use python on windows with full submodule support without installation☆30Jan 23, 2025Updated last year
- Early Bird Cryo Injections – APC-based DLL & Shellcode Injection via Pre-Frozen Job Objects☆146Apr 6, 2025Updated last year
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Object file loader implemented as a post-ex DLL for asynchronous BOF execution.☆29Jul 23, 2026Updated 2 weeks ago
- Rehashing APIs to prevent hash based detection☆14Jan 7, 2025Updated last year
- Command Augmentation support for BOFs and .NET assemblies across agents☆50Jul 30, 2026Updated last week
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago
- Library of BOFs to interact with SQL servers☆16Dec 6, 2024Updated last year
- Playing with packets in C#☆15Aug 16, 2024Updated last year
- Novel Windows process injection: assembles existing open handles (process & thread), natural RWX regions, and special user APC (NtQueueAp…☆74Feb 17, 2026Updated 5 months ago
- Evasive shellcode loader with indirect syscalls, Thread name-calling allocation, PoolParty injection☆10Feb 26, 2025Updated last year
- Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.☆42Aug 5, 2025Updated last year
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Using call gadgets to break the call stack signature used by Elastic on proxying a module load. Provided as a Crystal Palace shared libra…☆88Nov 6, 2025Updated 9 months ago
- DeadManSwitch in rust with several triggers (remote local and network)☆24Nov 19, 2025Updated 8 months ago
- Shroudware is a compile-time obfuscation library implemented entirely in the C preprocessor.☆27Apr 12, 2026Updated 3 months ago
- FrostLock Injection is a freeze/thaw-based code injection technique that uses Windows Job Objects to temporarily freeze (suspend) a targe…☆46Apr 6, 2025Updated last year
- ☆22Jun 24, 2025Updated last year
- Example of call stack spoofing trough the construction of syntetic frames and stack manipulation☆37Jan 17, 2026Updated 6 months ago
- AES-GEM (AES Galois Extended Mode) implementation.☆14May 19, 2026Updated 2 months ago
- Anti Suspend and Detect Detaching from debuggers.☆17Apr 1, 2024Updated 2 years ago
- Sample Rust crate used to implement a VBS enclave in Rust☆48Jun 3, 2025Updated last year
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Evasion kit for Cobalt Strike☆31Jan 16, 2026Updated 6 months ago
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.☆56Mar 30, 2026Updated 4 months ago
- An ICMP channel for Beacons, implemented using Cobalt Strike’s External C2 framework.☆122Oct 6, 2025Updated 10 months ago
- Memory API proxy via signed mozglue.dll☆39Jun 25, 2026Updated last month
- Small external program that will attempt to detect and disable minhook hooks in a process☆27Dec 23, 2023Updated 2 years ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆119Dec 21, 2025Updated 7 months ago
- C# to read WIM files over the network without transferring the whole file☆40Jan 22, 2026Updated 6 months ago
- Dll injection through code page id modification in registry. Based on jonas lykk research☆16Jun 18, 2022Updated 4 years ago
- C2 Agent fully PIC for Mythic with advanced evasion capabilities, dotnet/powershell/shellcode/bof memory executions, lateral moviments, p…☆216Dec 30, 2025Updated 7 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Collection of red team techniques.☆70Apr 25, 2025Updated last year
- executing shellcode directly from a python variable☆30Dec 20, 2025Updated 7 months ago
- SafeHarbor revamped with Direct Syscalls using InlineWhispers3☆15Feb 16, 2026Updated 5 months ago
- Dumping processes using a kernel-mode driver.☆20Nov 10, 2021Updated 4 years ago
- Improved VMP Idea(detect anti-anti-debug tools by bug)☆51Jun 7, 2023Updated 3 years ago
- Advanced Malware Dropper & Evasion Toolkit for Authorized Red Teaming☆16Nov 24, 2025Updated 8 months ago
- PE Sections Packer + Loader for Windows - Packs a DLL/EXE file and maps it into the loader (C/C++)☆15Oct 19, 2025Updated 9 months ago