awesome-repositories.com
ब्लॉग
MCP
awesome-repositories.com

AI-संचालित खोज के साथ बेहतरीन ओपन-सोर्स रिपॉजिटरी खोजें।

एक्सप्लोर करेंक्यूरेटेड खोजेंओपन-सोर्स विकल्पसेल्फ-होस्टेड सॉफ्टवेयरब्लॉगसाइटमैप
प्रोजेक्टMCP सर्वरहमारे बारे मेंहम रैंकिंग कैसे करते हैंप्रेस
कानूनीगोपनीयताशर्तें
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

22 रिपॉजिटरी

Awesome GitHub RepositoriesIn-Memory Payload Execution

Techniques for executing malicious code directly in volatile memory to avoid disk-based detection.

Distinct from In-Memory Decompression Runtimes: None of the candidates refer to offensive security payloads; they refer to high-performance data storage or decompressed runtimes.

Explore 22 awesome GitHub repositories matching security & cryptography · In-Memory Payload Execution. Refine with filters or upvote what's useful.

Awesome In-Memory Payload Execution GitHub Repositories

AI के साथ बेहतरीन रिपॉजिटरी खोजें।हम AI का उपयोग करके सबसे सटीक रिपॉजिटरी खोजेंगे।
  • samratashok/nishangsamratashok का अवतार

    samratashok/nishang

    9,951GitHub पर देखें↗

    Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows targets. It functions as a post-exploitation toolkit and payload generator to automate attacks and manage remote targets. The project provides specialized capabilities for bypassing security controls, such as disabling the Antimalware Scan Interface and employing in-memory execution to avoid disk-based detection. It includes a variety of stealthy command and control mechanisms, utilizing non-standard channels like DNS TXT records, ICMP traffic, and webmail for communication a

    Runs scripts and shellcode directly in system memory to evade disk-based forensic detection.

    PowerShellactivedirectoryhackinginfosec
    GitHub पर देखें↗9,951
  • malwaredllc/byobmalwaredllc का अवतार

    malwaredllc/byob

    9,478GitHub पर देखें↗

    This project is a post-exploitation framework and command and control platform designed for security research and penetration testing. It functions as a remote access tool consisting of a central command server and encrypted executable payloads that establish reverse shell connections. The system utilizes a web-based dashboard for multi-client administration, allowing for remote host monitoring and direct shell access through an in-browser terminal. It generates cross-platform, encrypted binaries that employ a multi-stage delivery chain and a key exchange mechanism to secure communications.

    Allows loading scripts and third-party packages directly into remote process memory to avoid disk artifacts.

    Python
    GitHub पर देखें↗9,478
  • n1nj4sec/pupyn1nj4sec का अवतार

    n1nj4sec/pupy

    8,942GitHub पर देखें↗

    Pupy is a command and control framework and post-exploitation suite used for remote administration and system management. It functions as a cross-platform tool for deploying payloads and controlling multiple remote agents through encrypted communication channels. The framework features a multi-platform payload generator that creates custom executable files using configurable network launchers. It employs a network traffic obfuscator that stacks encryption and obfuscation protocols to hide communication from observation. The system provides capabilities for in-memory code execution, remote pr

    Executes scripts and binaries directly in volatile memory to avoid leaving forensic traces on physical disks.

    Pythonandroidbackdoorlinux
    GitHub पर देखें↗8,942
  • lolbas-project/lolbasLOLBAS-Project का अवतार

    LOLBAS-Project/LOLBAS

    8,323GitHub पर देखें↗

    LOLBAS is a curated database and knowledge base of signed Windows binaries that can be misused to bypass security restrictions and execute unauthorized code. It serves as a technical registry that maps trusted system files to their functional capabilities and the offensive tactics they enable. The project distinguishes itself by providing a capability-driven indexing system and a tactics registry that relates legitimate binary functionality to known security evasion techniques. It includes an association layer that links specific system binaries to attack patterns and tactical objectives, pro

    Catalogues the use of signed binaries to execute libraries and scripts in memory to avoid detection.

    XSLTblueteamdfirliving-off-the-land
    GitHub पर देखें↗8,323
  • k8gege/k8toolsk8gege का अवतार

    k8gege/K8tools

    6,167GitHub पर देखें↗

    K8tools is a multi-stage attack framework that combines memory-only payload execution, credential testing, port forwarding, privilege escalation, and physical USB-based keystroke injection for comprehensive system compromise. At its core, the Ladon PowerShell module loads a multi-function scanner directly into memory, enabling command execution without writing files to disk, while supporting memory-only payload delivery that downloads and runs obfuscated shellcode or PowerShell commands to evade antivirus detection. The framework distinguishes itself through its breadth of integrated capabili

    Downloads and runs obfuscated shellcode or PowerShell commands directly in memory to evade antivirus detection.

    PowerShell0daybrute-forcebypass
    GitHub पर देखें↗6,167
  • balloonwj/cppguideballoonwj का अवतार

    balloonwj/CppGuide

    6,030GitHub पर देखें↗

    CppGuide is a curated collection of educational resources and practical guides focused on C++ server development, Linux kernel internals, concurrent programming, network protocols, and security exploitation. It provides structured learning paths for backend developers, covering everything from interview preparation to building high-performance network servers and understanding operating system fundamentals. The guide distinguishes itself by offering in-depth, hands-on tutorials that walk through real-world implementations, including building a Redis-like server from scratch, designing custom

    Teaches running shellcode entirely from memory to avoid disk forensics, a key exploitation technique.

    GitHub पर देखें↗6,030
  • ne0nd0g/merlinNe0nd0g का अवतार

    Ne0nd0g/merlin

    5,555GitHub पर देखें↗

    Merlin एक क्रॉस-प्लेटफॉर्म कमांड एंड कंट्रोल फ्रेमवर्क और रिमोट एक्सेस टूल है। यह पोस्ट-एक्सप्लॉइटेशन समन्वय के लिए एक सर्वर और एजेंट सिस्टम प्रदान करता है, जो सुरक्षित संचार और कई ऑपरेटिंग सिस्टम पर कमांड निष्पादित करने के लिए HTTP/2 फ्रेमवर्क का उपयोग करता है। इस प्रोजेक्ट में एक इन-मेमोरी कोड निष्पादन इंजन है जो डिस्क पर फाइलें लिखे बिना सीधे प्रोसेस के भीतर असेंबली और शेलकोड चलाता है। यह पीयर-टू-पीयर नेटवर्क के माध्यम से एक विकेंद्रीकृत संचार आर्किटेक्चर लागू करता है, जिससे एजेंट डायरेक्ट बाइंड या रिवर्स कनेक्शन के माध्यम से डेटा का आदान-प्रदान कर सकते हैं। डिटेक्शन से बचने के लिए, फ्रेमवर्क में ट्रैफिक ऑब्फस्केशन टूल्स शामिल हैं जो TLS फिंगरप्रिंट को संशोधित करते हैं और संचार पैटर्न को छिपाने के लिए कॉन्फ़िगर करने योग्य पैकेट पैडिंग जोड़ते हैं। सुरक्षा को एन्क्रिप्टेड एजेंट संचार, सिमेट्रिक ट्रैफिक एन्क्रिप्शन और आइडेंटिटी वैलिडेशन के लिए एसिमेट्रिक क्रिप्टोग्राफिक हैंडशेक के माध्यम से मैनेज किया जाता है। सिस्टम कमांड लाइन इंटरफेस के माध्यम से मल्टी-यूज़र एक्सेस समन्वय का समर्थन करता है, जो रेड टीम इंफ्रास्ट्रक्चर के भीतर वितरित एजेंटों के प्रबंधन को सक्षम बनाता है।

    Executes assemblies and shellcode directly in volatile memory to avoid writing files to disk.

    Go
    GitHub पर देखें↗5,555
  • tjanczuk/edgetjanczuk का अवतार

    tjanczuk/edge

    5,439GitHub पर देखें↗

    यह प्रोजेक्ट एक पॉलीग्लॉट रनटाइम ब्रिज और इंटरऑप फ्रेमवर्क है जिसे एक ही ऑपरेटिंग सिस्टम प्रोसेस के भीतर .NET और Node.js कोड को निष्पादित करने के लिए डिज़ाइन किया गया है। यह एक क्रॉस-रनटाइम निष्पादन इंजन और इन-प्रोसेस स्क्रिप्टिंग होस्ट के रूप में कार्य करता है, जो क्रॉस-प्रोसेस संचार ओवरहेड को खत्म करने के लिए Common Language Runtime और JavaScript वातावरण के बीच द्वि-दिशात्मक संचार और डेटा एक्सचेंज को सक्षम बनाता है। यह फ्रेमवर्क द्वि-दिशात्मक एसिंक्रोनस कॉलबैक्स और विभिन्न प्रबंधित ऑब्जेक्ट टाइप्स के बीच बाइनरी बफर्स व सीरियलाइज़ेबल मानों के स्वचालित डेटा मार्शलिंग के लिए एक सिस्टम प्रदान करके खुद को अलग करता है। यह एक सामान्य कंपाइलर मॉडल का लाभ उठाकर एक चल रहे एप्लिकेशन के भीतर कई भाषाओं से सोर्स फाइल्स या इनलाइन स्क्रिप्ट्स के संकलन और निष्पादन की अनुमति देता है। यह प्रोजेक्ट बैकग्राउंड थ्रेड्स में एसिंक्रोनस टास्क ऑफलोडिंग, वेब फ्रेमवर्क मिडलवेयर के रूप में बाहरी लॉजिक का एकीकरण और एसिंक्रोनस SQL निष्पादन सहित क्षमताओं की एक विस्तृत श्रृंखला को कवर करता है। यह क्रॉस-रनटाइम एक्सेप्शन मैपिंग के लिए ऑब्जर्वेबिलिटी टूल्स भी प्रदान करता है और प्रबंधित व नेटिव प्रोसेस डिबगिंग दोनों का समर्थन करता है।

    Compiles scripts from target languages into delegates and exposes them as proxies for seamless execution.

    C++
    GitHub पर देखें↗5,439
  • hackplayers/evil-winrmHackplayers का अवतार

    Hackplayers/evil-winrm

    5,403GitHub पर देखें↗

    Evil-WinRM is a penetration testing tool and interactive remote shell designed for managing and executing commands on remote Windows systems via the WinRM protocol. It functions as a security utility for auditing Windows environments through remote command execution and credential manipulation. The tool distinguishes itself through its authentication capabilities, acting as both a Kerberos authentication client using ticket-based files and an NTLM pass-the-hash client that accesses services using password hashes instead of plaintext credentials. To evade detection, it supports in-memory paylo

    Implements techniques to execute PowerShell scripts directly in volatile memory to evade disk-based security detection.

    Ruby
    GitHub पर देखें↗5,403
  • k8gege/ladonk8gege का अवतार

    k8gege/Ladon

    5,297GitHub पर देखें↗

    Ladon is an internal network penetration scanner and vulnerability assessment tool designed to identify high-risk security flaws and assets across network segments. It operates as a fileless security scanner, executing its engine and modules directly in memory to avoid leaving a disk footprint on target systems. The project is distinguished by its integration as a plugin for command beacons, specifically within the Cobalt Strike framework. This allows for memory-resident network discovery and vulnerability detection. It further supports stealth operations through payload and script obfuscatio

    Executes scanning engines and modules directly in volatile memory to avoid leaving disk-based footprints.

    C#brute-forceexpexploit
    GitHub पर देखें↗5,297
  • thewover/donutTheWover का अवतार

    TheWover/donut

    4,461GitHub पर देखें↗

    Donut is a toolset for loading and executing payloads in memory, featuring a position-independent shellcode generator, an in-memory payload injector, and a .NET assembly loader. It is designed to convert executable files and scripts into shellcode that can be executed within the memory space of a remote process without writing files to disk. The project specializes in security evasion through memory-based patching and payload obfuscation using symmetric block ciphers and compression. It includes a remote payload stager to retrieve encrypted modules from HTTP or DNS servers during runtime, red

    Loads the .NET CLR into unmanaged processes to execute managed assemblies entirely from memory.

    C
    GitHub पर देखें↗4,461
  • node-ffi/node-ffinode-ffi का अवतार

    node-ffi/node-ffi

    4,322GitHub पर देखें↗

    node-ffi is a foreign function interface library for Node.js that enables calling functions from native C dynamic libraries without writing manual C++ bindings. It serves as a system for loading shared objects and DLLs into process memory, translating JavaScript values into binary representations, and executing external binaries at runtime. The project utilizes a wrapper around the libffi library to construct call frames and execute native functions with dynamic arguments. It distinguishes itself by providing a native memory manager for allocating raw pointers and a mapping system that connec

    Creates function pointers in memory that allow native libraries to trigger JavaScript callbacks.

    JavaScript
    GitHub पर देखें↗4,322
  • rogandawes/p4wnp1RoganDawes का अवतार

    RoganDawes/P4wnP1

    4,350GitHub पर देखें↗

    P4wnP1 is a hardware-based USB HID attack platform and peripheral emulator. It functions as a tool for emulating USB keyboards and mice to execute automated keystroke payloads, as well as a WiFi-enabled remote access tool that provides a wireless bridge for network relay and SSH access. The project is distinguished by its ability to establish covert bidirectional communication channels and remote shells using raw HID reports, specifically to bridge air-gapped systems. It further enables wireless network interception and the routing of network traffic over WiFi to facilitate man-in-the-middle

    Delivers and runs multi-stage PowerShell payloads entirely in system memory without writing to disk.

    Python
    GitHub पर देखें↗4,350
  • trustedsec/unicorntrustedsec का अवतार

    trustedsec/unicorn

    3,917GitHub पर देखें↗

    Unicorn is a collection of utilities for generating malicious HTA files, VBA macros, encoded PowerShell commands, and memory-resident shellcode injection frameworks. It provides tools to create payloads designed to achieve remote code execution by bypassing security controls. The project focuses on weaponizing office documents through VBA macros and formulas, generating HTA attack vectors, and creating encoded PowerShell payloads. It includes a shellcode injection framework to wrap external shellcode for direct execution in system memory. The toolkit covers binary-to-base64 conversion for ce

    Injects shellcode directly into volatile memory to establish remote access and evade disk-based antivirus.

    Python
    GitHub पर देखें↗3,917
  • hackerschoice/thc-tips-tricks-hacks-cheat-sheethackerschoice का अवतार

    hackerschoice/thc-tips-tricks-hacks-cheat-sheet

    3,853GitHub पर देखें↗

    This project is a comprehensive command-line reference and toolkit designed for Linux system administration and network security assessment. It provides a collection of technical snippets and operational guides focused on managing remote environments, orchestrating shell sessions, and executing administrative tasks through native terminal utilities. The repository distinguishes itself by offering specialized techniques for stealthy operations and infrastructure manipulation. It covers methods for establishing encrypted tunnels to bypass firewalls, obfuscating process identities and command hi

    Executes code directly in volatile memory to avoid writing artifacts to disk and evade file-based detection.

    Shell
    GitHub पर देखें↗3,853
  • nathanlopez/stitchnathanlopez का अवतार

    nathanlopez/Stitch

    3,532GitHub पर देखें↗

    Stitch is a command and control framework and post-exploitation toolkit designed for managing multiple remote systems from a central server. It functions as a remote administration tool and payload builder, enabling the execution of commands and the deployment of agents across different operating systems. The project features a cross-platform builder for generating custom executable agents with configurable network bindings and boot behaviors. It utilizes encrypted communication channels to secure traffic between the controller and remote clients, and it supports the execution of dynamic scri

    Enables the execution of dynamic scripts on remote agents to add new capabilities without recompiling the binary.

    Pythoncross-platformkeyloggerlinux
    GitHub पर देखें↗3,532
  • byt3bl33d3r/offensivenimbyt3bl33d3r का अवतार

    byt3bl33d3r/OffensiveNim

    3,033GitHub पर देखें↗

    OffensiveNim is a red teaming framework and post-exploitation toolkit developed in Nim. It provides a collection of low-level primitives and a Windows API wrapper designed for offensive security operations, including malware development and shellcode loading. The project focuses on evasion and obfuscation through techniques such as API unhooking, direct system calls, and anti-debugging mechanisms. It features diverse payload delivery methods, including reflective binary loading, the execution of .NET assemblies via CLR hosting, and various shellcode injection techniques using fibers, COM obje

    Loads the .NET Common Language Runtime into unmanaged processes to execute assemblies reflectively.

    Nim
    GitHub पर देखें↗3,033
  • trickster0/offensiverusttrickster0 का अवतार

    trickster0/OffensiveRust

    2,984GitHub पर देखें↗

    OffensiveRust is a red team toolkit and malware development kit written in Rust. It serves as an evasion framework and post-exploitation library, providing a collection of offensive security primitives and a Windows API wrapper for interacting with low-level system functions and undocumented APIs. The project focuses on bypassing security software through direct system calls, memory obfuscation, and stealthy payload execution. It implements techniques to defeat static binary analysis via compile-time string encryption and payload obfuscation, while avoiding detection using parent process ID s

    Implements techniques to run binary payloads from unbacked memory regions to avoid disk-based detection.

    Rust
    GitHub पर देखें↗2,984
  • 1y0n/av_evasion_tool1y0n का अवतार

    1y0n/AV_Evasion_Tool

    2,761GitHub पर देखें↗

    This project is a security research utility designed to evaluate and test the detection capabilities of antivirus products. It provides a framework for generating custom, memory-resident loaders that execute payloads directly within a process memory space, bypassing standard file-based execution monitoring. The tool distinguishes itself by employing compiler-driven generation to create unique executable binaries, which avoids the predictable patterns associated with pre-compiled security software. It incorporates dynamic control flow obfuscation to hinder static analysis and utilizes payload

    Executes malicious payloads directly in volatile memory to avoid disk-based signature scanning.

    C#
    GitHub पर देखें↗2,761
  • specterops/bloodhoundSpecterOps का अवतार

    SpecterOps/BloodHound

    2,789GitHub पर देखें↗

    BloodHound is an identity risk management platform and graph-based attack path analyzer used to map identity relationships and permissions in Active Directory. It functions as a security tool for auditing directory services, uncovering unintended privilege relationships, and visualizing sequences of permissions that can lead to domain compromise. The project differentiates itself as a comprehensive adversary emulation framework that coordinates remote agents and executes post-exploitation commands. It includes a reverse proxy for bypassing multi-factor authentication via real-time session hij

    Executes specialized assemblies and binary modules directly in process memory to evade disk-based detection.

    Go
    GitHub पर देखें↗2,789
पिछला12अगला
  1. Home
  2. Security & Cryptography
  3. In-Memory Payload Execution

सब-टैग एक्सप्लोर करें

  • CLR Hosting Loaders1 सब-टैगLoads the .NET Common Language Runtime into unmanaged processes using the Unmanaged CLR Hosting API. **Distinct from In-Memory Payload Execution:** Distinct from In-Memory Payload Execution: specifically loads the .NET CLR runtime into a process, not just executing arbitrary shellcode.
  • In-Memory Payload EncryptorsEncrypts .NET assemblies with the Chaskey block cipher and a random key, then erases the decrypted copy after loading to evade memory scanners. **Distinct from In-Memory Payload Execution:** Distinct from In-Memory Payload Execution: focuses on encrypting payloads in memory and erasing decrypted copies, not just executing them.
  • Native Callback StubsExecutable memory regions that act as function pointers for native code to trigger managed callbacks. **Distinct from In-Memory Payload Execution:** Focuses on legitimate interop callbacks rather than security-related payload execution.
  • Script-Based DLL LoadersGeneration of scripts that encode and load managed DLLs directly into memory. **Distinct from In-Memory Payload Execution:** Specifically covers the generation of a loader script to wrap a DLL, not just the act of in-memory execution.
  • Scripting Language ExecutionsRunning VBScript and JScript code directly from memory using the IActiveScript interface. **Distinct from In-Memory Payload Execution:** Distinct from In-Memory Payload Execution: focuses on script language execution via IActiveScript, not general binary payloads.
  • Serialized Payload Execution1 सब-टैगExecuting arbitrary code by passing serialized payloads through trusted binary proxies. **Distinct from In-Memory Payload Execution:** Specifically focuses on the use of serialized data as the execution trigger via proxy binaries.