This is your work, valued

̷K̷i̷r̷k̷ ̷T̷r̷y̷c̷h̷e̷l̷

Expert
@Teach2Breach

MALicious softWARE

Tempest. A command and control framework written in rust.

393

moonwalk. find dll base addresses without PEB WALK

170

stargate. Locate dlls and function addresses without PEB Walk and EAT parsing

110

mal_ex. Source code for complete MALicious softWARE books I & II

80

noldr. Dynamically resolve API function addresses at runtime in a secure manner.

74

pool_party_rs. remote process injections using pool party techniques

71

phantom_persist_rs. Rust implementation of phantom persistence technique documented in https://blog.phantomsec.tools/phantom-persistence

65

early_cascade_inj_rs. early cascade injection PoC based on Outflanks blog post, in rust

64

snapinject_rs. A remote process injection using process snapshotting based on https://gitlab.com/ORCA000/snaploader , in rust. It creates a sacrificial process, takes a snapshot of the process, and injects shellcode into it.

50

schtask. Rust implementation, creating a scheduled task programmatically with user logon trigger.

47

dll2shell. converts sRDI compatible dlls to shellcode

39

Red_Team_Rust. Collection of Rust repos useful for Red Teamers.

34

hollow_rs. A Rust PoC implementation of the Early Bird process hollowing technique, inspired by https://github.com/boku7/HOLLOW.

31

rpeloader. use python on windows with full submodule support without installation

30

byont. bring your own clean ntdll (or other MS dlls)

29

nt_unhooker. demo unhooking functions in ntdll

28

dev. maldev obviously

28

NtCreateUserProcess_rs. example using NtCreateUserProcess in rust

19

rust_api_demo. various methods of making API calls

19

rekkoex. Rust

18

openai. Red Team Projects with chat.openai.com.

17

rust_template. Rust

11

rpi. rust library for performing remote process injection, originally written for use in Tempest c2 project

10

debug_inject_rs. Rust

9

rust_pyramid. Rust project that leverages the signed embeddable python package to evade EDR.

8

RustySpy. A powerful Windows UI monitoring and DNS exfiltration tool written in Rust, combining advanced UI event capture capabilities with secure data exfiltration and EDR suppression features.

6

rusternals. A rust code notebook for working with windows internals.

5

offensiveswift. Swift

5

NomadLoader. An advanced utility for converting Windows Portable Executable (PE) files to position-independent code (PIC) shellcode. It enables executable content to be executed from any memory location without requiring traditional loading or relocation.

4

macdev. maldev but for mac

4

Rust-for-Malware-Development. This repository contains my complete resources and coding practices for malware development using Rust 🦀.

4

Supernova. Real fucking shellcode encryptor & obfuscator tool

3

rustpivotclient. just the client

3

PhantomKeystroke. An advanced attribution deception tool that adds subtle, region-specific fingerprints to command-line operations to mislead forensic analysis. It seamlessly integrates with C2 frameworks and provides realistic keyboard patterns from different regions while maintaining full command functionality.

3

MalDev-Analyzer-MCP. Built for red teamers, by red teamers - an MCP tool for malware development, OPSEC testing, and supporting custom loader design during red team engagements.

2

Shelter. ROP-based sleep obfuscation to evade memory scanners

2

x64asm. Learning x64 assembly with MASM

2

RustPivot. Reverse SOCKS5 Proxy Written in Rust

2

dll-builder. Creates a DLL that runs a payload once injected into a process.

2

shellcode-plain-sight. Hiding shellcode in plain sight within a large memory region. Inspired by technique used by Raspberry Robin's Roshtyak

2

Snapshotting_rs. Rust

2

kernel-callback-removal. kernel callback removal (Bypassing EDR Detections)

2

azure_scripts. Scripts for attacking azure

1

windows-XP-SP1. 网上泄露的Windows XP SP1 source code

1

FaceDancer. FaceDancer is an exploitation tool aimed at creating hijackable, proxy-based DLLs by taking advantage of COM-based system DLL image loading

1

rust-remote-injection-nix. Shellcode injection to a remote linux process in rust

1

RustVEHSyscalls. Rust port of LayeredSyscall, designed to perform indirect syscalls while generating legitimate API call stack frames by abusing Vectored Exception Handling (VEH) to bypass user-land EDR hooks in Windows.

1

srdi-rs. Rusty Shellcode Reflective DLL Injection (sRDI)

1

turnt. A tool designed for smuggling interactive command and control traffic through legitimate TURN servers hosted by reputable providers such as Zoom.

1

reloader. Reflective DLL self-loading as a library

1

pdfdropper. PDF dropper Red Team Scenairos

1