Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.
-
Updated
Feb 19, 2026 - C
Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.
🚫💾 Run binaries straight from memory in Linux
A library for loading ELF from memory and/or making Linux syscalls on Android written in pure Java.
Interactive Shell and Command Execution over Named-Pipes (SMB) for Fileless lateral movement
A library for loading and executing PE (Portable Executable) from memory without ever touching the disk
IronPE is a Windows PE manual loader written in Rust for both x86 and x64 PE files.
Slui File Handler Hijack UAC Bypass Local Privilege Escalation
A C# PE loader for x64 and x86 PE files.
Elfina is a multi-architecture ELF loader written in Rust, supporting x86 and x86-64 binaries.
Python program Fileless-PE.py generates a Python script (PEloader.py) to load a DLL or EXE file from a given URL. It provides functionality to specify a method to execute if the file is a DLL. The script utilizes the pythonmemorymodule library for memory manipulation.
Powerful script for logical obfuscation of powershell scripts
A Golang shellcode loader that receives payloads via ICMP packets from a C2 server to bypass firewalls
LOLGEN: Living Off The Land Payload Generator
Powershell Malware
Materials from the speech "How to protect yourself from hidden web shells"
Add a description, image, and links to the fileless topic page so that developers can more easily learn about it.
To associate your repository with the fileless topic, visit your repo's landing page and select "manage topics."