Alien3407's starred repositories

HackBrowserData

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

sliver

Adversary Emulation Framework

Language:GoLicense:GPL-3.0Stargazers:8122Issues:147Issues:725

EvilClippy

A cross-platform assistant for creating malicious MS Office documents. Can hide VBA macros, stomp VBA code (via P-Code) and confuse macro analysis tools. Runs on Linux, OSX and Windows.

Language:C#License:GPL-3.0Stargazers:2093Issues:90Issues:46

Platypus

:hammer: A modern multiple reverse shell sessions manager written in go

Language:GoLicense:LGPL-3.0Stargazers:1491Issues:30Issues:115

AVIator

Antivirus evasion project

Language:C#License:GPL-3.0Stargazers:1029Issues:36Issues:17

SourcePoint

SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.

RunasCs

RunasCs - Csharp and open version of windows builtin runas.exe

Language:C#License:GPL-3.0Stargazers:963Issues:16Issues:11

darkarmour

Windows AV Evasion

Language:PythonLicense:MITStargazers:723Issues:14Issues:10

DeathSleep

A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementing page protection changes during no execution.

FlavorTown

Various ways to execute shellcode

Language:C#License:BSD-3-ClauseStargazers:473Issues:10Issues:0

inject-assembly

Inject .NET assemblies into an existing process

Language:CLicense:GPL-3.0Stargazers:472Issues:10Issues:3

ScareCrow-CobaltStrike

Cobalt Strike script for ScareCrow payloads intergration (EDR/AV evasion)

Language:PythonLicense:MITStargazers:453Issues:9Issues:8

Apollo

A .NET Framework 4.0 Windows Agent

Language:C#License:BSD-3-ClauseStargazers:439Issues:19Issues:33

Brute-Ratel-C4-Community-Kit

This repository contains scripts, configurations and deprecated payload loaders for Brute Ratel C4 (https://bruteratel.com/)

Language:CLicense:GPL-3.0Stargazers:253Issues:9Issues:0

Orca

Incomplete project

SandboxDefender

C# code to Sandbox Defender (and most probably other AV/EDRs).

Kramer

The next level 100% Python obfuscator.

Language:PythonLicense:EPL-2.0Stargazers:126Issues:3Issues:17

CobaltStrike_BOF_Collections

Useful Cobalt Strike BOFs found or used during engagements

dearg-thread-ipc-stealth

A novel technique to communicate between threads using the standard ETHREAD structure

Language:CStargazers:108Issues:8Issues:0

T.D.P

Using Thread Description To Hide Shellcode

Language:C++Stargazers:100Issues:0Issues:0

DarkFinger-C2

Windows TCPIP Finger Command / C2 Channel and Bypassing Security Software

Language:PythonLicense:NOASSERTIONStargazers:63Issues:2Issues:0

ProcessGhosting

Small POC for process ghosting

Language:C#Stargazers:39Issues:1Issues:0

UAC-Bypass

Bypassing windows uac, however its an old approach/method but its still unpatched ¯\_(ツ)_/¯

onefile_python

Run python from a single exe

Language:NimLicense:NOASSERTIONStargazers:34Issues:2Issues:0

titan

Golang C2 and Beacon/Agent built from the ground up for scalability and expandability

gizligizli

A steganography based shellcode hider to bypass AV

Language:PythonLicense:MITStargazers:13Issues:1Issues:1

Mischief-Encoder

Shellcode encoder for AV bypass and execution

Language:PythonStargazers:9Issues:2Issues:0