fileless-malware
Here are 24 public repositories matching this topic...
An open-source, C#-based remote administration tool (RAT), enabling complete control of a remote Windows machine, designed for legitimate remote administration and security testing of Windows systems.
-
Updated
Apr 9, 2026 - C#
IronPE is a Windows PE manual loader written in Rust for both x86 and x64 PE files.
-
Updated
Mar 10, 2026 - Rust
execute PE in memory Filelessly
-
Updated
Feb 8, 2025 - Python
A C# PE loader for x64 and x86 PE files.
-
Updated
Mar 9, 2026 - C#
Elfina is a multi-architecture ELF loader written in Rust, supporting x86 and x86-64 binaries.
-
Updated
Mar 15, 2026 - Rust
Plaguards: Open Source PowerShell Deobfuscation and IOC Detection Engine for Blue Teams. [Presented at Black Hat Asia and USA 2025 Arsenal]
-
Updated
Jan 4, 2026 - Python
Origami Crypter with an updated version of the stub that bypasses windows defender.
-
Updated
Mar 13, 2025
Ghost-C2 is a command-and-control framework written entirely in pure x64 Linux Assembly with no libc dependencies. Every operation goes through direct syscalls. There are no import tables, no dynamic linker artifacts, and no disk writes. The C2 channel runs over raw ICMP sockets, hiding inside standard diagnostic traffic.
-
Updated
Apr 18, 2026 - Assembly
Awesome Fileless Malware Scientific Research
-
Updated
Dec 24, 2025
Selling crypter / crypter services bypassing windows defender. Private stub for each purchase. 50 dollars.
-
Updated
Apr 6, 2025
Awesome Fileless Malware
-
Updated
Dec 1, 2025
Proof of Concept que replica la técnica de evasión avanzada utilizada por APT35 (Charming Kitten) en su backdoor "PowerLess" (2021-2022).
-
Updated
Jan 30, 2026
Fileless Persistence Engine -- 7 techniques that survive reboot without writing a single file to disk. Pure Go.
-
Updated
Mar 1, 2026 - Go
For educational and cybersecurity purposes.
-
Updated
Oct 29, 2025 - HTML
Fileless Malware Cookbook
-
Updated
Apr 1, 2026
PowerShell benchmark and robust LOTL/fileless detection artifact with v9 and v10 evaluation outputs.
-
Updated
Apr 13, 2026 - PowerShell
This case, centered on a PowerShell download cradle, illustrates one of the most common but under-analyzed threats in modern enterprise environments.
-
Updated
May 23, 2025 - Jupyter Notebook
This is a lightweight Command and Control (C2) tool built with Rust, featuring a minimal set of core functionalities
-
Updated
Nov 28, 2025 - Rust
Fetch a remote C# Assembly and execute it in memory using Assembly.Load
-
Updated
Apr 8, 2025 - Python
Improve this page
Add a description, image, and links to the fileless-malware topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the fileless-malware topic, visit your repo's landing page and select "manage topics."