Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.
-
Updated
Jul 28, 2026 - C
Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.
Template-Driven AV/EDR Evasion Framework
CloakifyFactory - Data Exfiltration & Infiltration In Plain Sight; Convert any filetype into list of everyday strings, using Text-Based Steganography; Evade DLP/MLS Devices, Defeat Data Whitelisting Controls, Social Engineering of Analysts, Evade AV Detection
Antivirus evasion project
Multilayered AV/EDR Evasion Framework (no longer actively maintained)
PoC Implementation of a fully dynamic call stack spoofer
Loader, dropper generator with multiple features for bypassing client-side and network-side countermeasures.
AV Evasion Tool For Red Team Ops
Crypter, binder & downloader with native & .NET stub, evasive by design, user friendly UI
AV/EDR killer leveraging vulnerable kernel drivers
C++ self-Injecting dropper based on various EDR evasion techniques.
C# Based Universal API Unhooker
Golang library for malware development
Materials for the workshop "Red Team Ops: Havoc 101"
indirect syscalls for AV/EDR evasion in Go assembly
Go shellcode loader that combines multiple evasion techniques
An online AV evasion platform written in Springboot (Golang, Nim, C) supports embedded, local and remote loading of Shellocde methods.
The following two code samples can be used to understand the difference between direct syscalls and indirect syscalls
Automated Tool That Generates The Perfect Meterpreter Powershell Payload
A better version of Xencrypt.Xencrypt it self is a Powershell runtime crypter designed to evade AVs.
To associate your repository with the av-evasion topic, visit your repo's landing page and select "manage topics."