- TM. Codepulze
- Mem
-
-
Ebyte-amsi-patchless-vehhwbp Public
Patchless AMSI bypass using hardware breakpoints and a vectored exception handler to intercept AmsiScanBuffer and AmsiScanString before they execute. The bypass reads the 5th parameter (the AMSI re…
-
AntiDebugEP Public
Anti-debug tool that detects INT3 breakpoints at the program’s entry point using a TLS callback
-
HandleHijacker Public
HandleHijacker is a low-level Windows utility written in Go that lets you inspect running processes, extract files that processes have open, and optionally close handles to those files, that lets u…
-
ExitPatcher Public
Prevent in-process process termination by patching exit APIs
-
NoMoreStealers Public
NoMoreStealers is a Windows file system minifilter driver that protects sensitive user data from untrusted processes.
-
Ebyte-Syscalls Public
Obfuscating function calls using Vectored Exception Handlers by redirecting execution through exception-based control flow. Uses byte swapping without memory or assembly allocation.
-
Detecting-Indirect-Syscalls Public
Detection of indirect syscall techniques using hardware breakpoints and vectored exception handling.
-
VK-Api-Amsi-Bypass Public
The Vulkan loader vulkan-1.dll has internal trampoline functions that perform checksum validation before executing callbacks., lets use that for our usage.
-
GoDefender Public
Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONLY.
-
CMD-Arg-Spoof Public
Manipulate PEB, and patch CmdArgs - RTL_USER_PROCESS_PARAMETERS..
-
TaskMgr-Troll Public
Troll TaskManager, and play with it .
-
Ebyte-Go-Morpher Public
Ebyte-Go-Morpher is a Go program that parses, analyzes, and rewrites Go source code to apply multiple layers of obfuscation. It operates directly on the Go Abstract Syntax Tree (AST) and generates …
-
Ebyte-ETW-Redirector Public
A lightweight tool that injects a custom assembly proxy into a target process to silently bypass ETW scanning by redirecting ETW calls to custom proxy.
-
Nyx-Full-Dll-Unhook Public
(EDR) Dll Unhooking = kernel32.dll, kernelbase.dll, ntdll.dll, user32.dll, apphelp.dll, msvcrt.dll.
-
Ebyte-AMSI-ProxyInjector Public
A lightweight tool that injects a custom assembly proxy into a target process to silently bypass AMSI scanning by redirecting AmsiScanBuffer calls. It suspends the target’s threads, patches the fun…
-
EByte-Pattern-AmsiPatch Public
Pattern-based AMSI bypass that patches AMSI.dll in memory by modifying comparison values, conditional jumps, and function prologues to neutralize malware scanning without modifying any files on disk.
-
EvilByte-Remote-AMSI-Bypass Public
Bypasses AMSI protection through remote memory patching and parsing technique.
-
PhantomDelay Public
PhantomDelay is a precise delay function that uses the Windows high resolution performance counter to pause your program for a specified number of seconds.
-
-
EByte-Ransomware Public
Go ransomware leveraging ChaCha20 and ECIES encryption with a web-based control panel.
-
GoRedOps Public
🦫 | GoRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team, with a specific focus on the Go programming language, all is made for educati…
-
Lifetime-Amsi-EtwPatch Public
Two in one, patch lifetime powershell console, no more etw and amsi!
-
PayloadCrypter Public
Go Based Crypter That Can Bypass Any Kinds Of Antivirus Products, payload crypter supports over 4 programming languages.
-
PyDefender Public
Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package.
-
Shellcode-Loader Public
This is way to load a shellcode, and obfuscate it, so it avoids scantime detection.
-
ThunderKitty-Ransomware Public
Ransomware written in go, encrypt - decrypt.
-
ThunderKitty Public
🔑 Open source stealer written in Go, all logs will be sent to Telegram bot.
-
veh-syscalls-shellcode Public
NFS
-
Staged-Shellcode-Loader Public
Beacuse it was leaked, enjoy use with donut.



