Tempest. A command and control framework written in rust.
393moonwalk. find dll base addresses without PEB WALK
170stargate. Locate dlls and function addresses without PEB Walk and EAT parsing
110mal_ex. Source code for complete MALicious softWARE books I & II
80noldr. Dynamically resolve API function addresses at runtime in a secure manner.
74pool_party_rs. remote process injections using pool party techniques
71phantom_persist_rs. Rust implementation of phantom persistence technique documented in https://blog.phantomsec.tools/phantom-persistence
65early_cascade_inj_rs. early cascade injection PoC based on Outflanks blog post, in rust
64snapinject_rs. A remote process injection using process snapshotting based on https://gitlab.com/ORCA000/snaploader , in rust. It creates a sacrificial process, takes a snapshot of the process, and injects shellcode into it.
50schtask. Rust implementation, creating a scheduled task programmatically with user logon trigger.
47dll2shell. converts sRDI compatible dlls to shellcode
39Red_Team_Rust. Collection of Rust repos useful for Red Teamers.
34hollow_rs. A Rust PoC implementation of the Early Bird process hollowing technique, inspired by https://github.com/boku7/HOLLOW.
31rpeloader. use python on windows with full submodule support without installation
30byont. bring your own clean ntdll (or other MS dlls)
29nt_unhooker. demo unhooking functions in ntdll
28dev. maldev obviously
28NtCreateUserProcess_rs. example using NtCreateUserProcess in rust
19rust_api_demo. various methods of making API calls
19rekkoex. Rust
18openai. Red Team Projects with chat.openai.com.
17rust_template. Rust
11rpi. rust library for performing remote process injection, originally written for use in Tempest c2 project
10debug_inject_rs. Rust
9rust_pyramid. Rust project that leverages the signed embeddable python package to evade EDR.
8RustySpy. A powerful Windows UI monitoring and DNS exfiltration tool written in Rust, combining advanced UI event capture capabilities with secure data exfiltration and EDR suppression features.
6rusternals. A rust code notebook for working with windows internals.
5offensiveswift. Swift
5NomadLoader. An advanced utility for converting Windows Portable Executable (PE) files to position-independent code (PIC) shellcode. It enables executable content to be executed from any memory location without requiring traditional loading or relocation.
4macdev. maldev but for mac
4Rust-for-Malware-Development. This repository contains my complete resources and coding practices for malware development using Rust 🦀.
4Supernova. Real fucking shellcode encryptor & obfuscator tool
3rustpivotclient. just the client
3PhantomKeystroke. An advanced attribution deception tool that adds subtle, region-specific fingerprints to command-line operations to mislead forensic analysis. It seamlessly integrates with C2 frameworks and provides realistic keyboard patterns from different regions while maintaining full command functionality.
3MalDev-Analyzer-MCP. Built for red teamers, by red teamers - an MCP tool for malware development, OPSEC testing, and supporting custom loader design during red team engagements.
2Shelter. ROP-based sleep obfuscation to evade memory scanners
2x64asm. Learning x64 assembly with MASM
2RustPivot. Reverse SOCKS5 Proxy Written in Rust
2dll-builder. Creates a DLL that runs a payload once injected into a process.
2shellcode-plain-sight. Hiding shellcode in plain sight within a large memory region. Inspired by technique used by Raspberry Robin's Roshtyak
2Snapshotting_rs. Rust
2kernel-callback-removal. kernel callback removal (Bypassing EDR Detections)
2azure_scripts. Scripts for attacking azure
1windows-XP-SP1. 网上泄露的Windows XP SP1 source code
1FaceDancer. FaceDancer is an exploitation tool aimed at creating hijackable, proxy-based DLLs by taking advantage of COM-based system DLL image loading
1rust-remote-injection-nix. Shellcode injection to a remote linux process in rust
1RustVEHSyscalls. Rust port of LayeredSyscall, designed to perform indirect syscalls while generating legitimate API call stack frames by abusing Vectored Exception Handling (VEH) to bypass user-land EDR hooks in Windows.
1srdi-rs. Rusty Shellcode Reflective DLL Injection (sRDI)
1turnt. A tool designed for smuggling interactive command and control traffic through legitimate TURN servers hosted by reputable providers such as Zoom.
1reloader. Reflective DLL self-loading as a library
1pdfdropper. PDF dropper Red Team Scenairos
1