Pyramid. a tool to help operate in EDRs' blind spots
772PythonMemoryModule. pure-python implementation of MemoryModule technique to load dll and unmanaged exe entirely from memory
340DojoLoader. Generic PE loader for fast prototyping evasion techniques
246ProcessStomping. A variation of ProcessOverwriting to execute shellcode on an executable's section
147ModuleShifting. Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes
135Embedder. Embedder is a collection of sources in different languages to embed Python interpreter with minimal dependencies
124talks. Repo containing my public talks
23python-bof-runner. Python inline shellcode injector that could be used to run BOFs by leveraging BOF2shellcode
8UnhookingPatch. Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime
4BouncyGate. HellsGate in Nim, but making sure that all syscalls go through NTDLL.DLL (as in RecycledGate).
3DropSpawn_BOF. CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking
2DInjector. Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL
2OffensivePipeline. OffensivePipeline allows to download, compile (without Visual Studio) and obfuscate C# tools for Red Team exercises.
1DarkLoadLibrary. LoadLibrary for offensive operations
1GregsBestFriend. GregsBestFriend process injection code created from the White Knight Labs Offensive Development course
1Packer_Development. Slides & Code snippets for a workshop held @ x33fcon 2024
1RWX-Dlls-for-manual-mapping. Here are a few rwx dlls your can use to manual map your cheat dll, they will prob get checked soon...
1Havoc-C2-Modification-YARA-Free. POC of modifying YARA signautre for Havoc C2
1FilelessRemotePE. Loading Fileless Remote PE from URI to memory with argument passing and ETW patching and NTDLL unhooking and No New Thread technique
1FOLIAGE. Public variation of FOLIAGE ( original developer )
1grimreaper. A improved memory obfuscation primitive using a combination of special and 'normal' Asynchronous Procedural Calls
1TitanLdr. Public variation of Titan Loader
1beacon. Former attempt at creating a independent Cobalt Strike Beacon
1