GitPedia

Shellcode resources

Resources About Shellcode

From alphaSeclab·Updated May 6, 2026·View on GitHub·

- Shellcode相关资源, 150+工具, 500+文章 - [English Version](https://github.com/alphaSeclab/shellcode-resources/blob/master/Readme_en.md) The project is first published in 2020. Key topics include: shellcode, shellcode-analysis, shellcode-convert, shellcode-decode, shellcode-development.

所有收集类项目

Shellcode

目录

<a id="046354d96bbc65ade966dc83ff7fe8ef"></a>开发&&编写


<a id="5489b8896792ff75d1e0971597d5829b"></a>shellen

<a id="7a69f4fc97964348552acb7c8472f1ab"></a>工具

<a id="e5dc2d01e8279adf30d34066b8c61aaf"></a>文章


<a id="4f71b3d96ccbb4433cd9582bf6b3b49c"></a>漏洞开发

<a id="1578f4dee1f7b9340b7923d72e67ca75"></a>工具

<a id="76612bdb96657fd5e6c663f76b738619"></a>文章


<a id="4137b4aa2b9562fbad4010b40c93c0b8"></a>编码&&解码

<a id="3ab819169565fb2ac49e4a7285b217fd"></a>工具

<a id="1d15b6ffe1202baecee2e63ceb01261c"></a>文章


<a id="2aad113ca8fd8b2ce5278b3c73afb637"></a>工具


<a id="ba82bf5ca275733d09434861aa4becf5"></a>文章

<a id="b79d65effe22d7dfa216cdfaaede7abd"></a>启动&&加载&&注入&&执行


<a id="c8f7f9913bbf6ca9ad62b2924a81c5a1"></a>注入

<a id="270623a2c94dd2e4a342f46262ee8ae1"></a>工具

<a id="f67fc5d20ddff852419d63d094cb17ba"></a>文章


<a id="4ad7253b703db90d80efccc99da781e5"></a>执行

<a id="b84580eec0d446e20ed9c774946f9325"></a>工具

<a id="9cdbcec9e7e4bf040fe9802dc4e1225b"></a>文章


<a id="2c78519e8cf84e3863d4c2374ead132f"></a>工具


<a id="4f9e0536cd4c8b6d7e3597c5c9315df5"></a>文章

<a id="c86cc38af95f4ccbc3d082b3883af702"></a>生成


<a id="20753578295f405b2fee3ae5659ee214"></a>工具

  • [693星][1m] [C] thewover/donut 生成位置无关的shellcode(x86,x64或AMD64 + x86),该shellcode从内存中加载.NET程序集、PE文件和其他Windows有效负载,并使用参数运行它们
  • [582星][2m] [Shell] r00t-3xp10it/venom shellcode 生成器、编译器、处理器(metasploit)
  • [552星][8m] [C++] nytrorst/shellcodecompiler 将C/C ++样式代码编译成一个小的、与位置无关且无NULL的Shellcode,用于Windows(x86和x64)和Linux(x86和x64)
  • [493星][1m] [Py] zdresearch/owasp-zsc Shellcode/混淆代码生成器
  • [90星][3y] [C++] gdelugre/shell-factory C++-based shellcode builder
  • [88星][2m] [Py] alexpark07/armscgen ARM Shellcode Generator
  • [80星][3y] [Py] hatriot/shellme simple shellcode generator
  • [63星][5y] [Py] veil-framework/veil-ordnance Veil-Ordnance is a tool designed to quickly generate MSF stager shellcode
  • [40星][3y] [Py] karttoon/trigen Trigen is a Python script which uses different combinations of Win32 function calls in generated VBA to execute shellcode.
  • [37星][3y] [C++] 3gstudent/shellcode-generater No inline asm,support x86/x64
  • [33星][2y] [HTML] rh0dev/shellcode2asmjs Automatically generate ASM.JS JIT-Spray payloads
  • [13星][4y] zdresearch/zcr-shellcoder-archive ZeroDay Cyber Research - ZCR Shellcoder Archive - z3r0d4y.com Shellcode Generator
  • [13星][1m] [C++] hoodoer/enneos Evolutionary Neural Network Encoder of Shenanigans. Obfuscating shellcode with an encoder that uses genetic algorithms to evolve neural networks to contain and output the shellcode on demand.
  • [10星][2m] [C#] clonemerge/shellgen Dynamic and extensible shell code generator with multiple output types which can be formatted in binary, hexadecimal, and the typical shellcode output standard.
  • [4星][2y] [Shell] thepisode/linux-shellcode-generator Experiments on Linux Assembly shellcodes injection
  • [1星][4m] [Py] ins1gn1a/woollymammoth Toolkit for manual buffer exploitation, which features a basic network socket fuzzer, offset pattern generator and detector, bad character identifier, shellcode carver, and a vanilla EIP exploiter

<a id="102a321d8be34fab263fe0559145b36c"></a>文章

<a id="4d515d3e53e9e4ae1f09bd9f4afc5b5a"></a>转换


<a id="eb5e32922251dc76e85ed094adbcacd9"></a>工具


<a id="1d87c2031d25482e324e0b3158e46806"></a>文章

<a id="9a0361c824e96f82eaec8829d14cf080"></a>分析


<a id="115b4bfacc38bd2fc9b7fa303b5c58ab"></a>漏洞


<a id="b636936039c6751d5e736ca2e52c8e1a"></a>工具

  • [203星][2y] [Py] rootlabs/smap Handy tool for shellcode analysis
  • [166星][2y] [C] oalabs/blobrunner Quickly debug shellcode extracted during malware analysis
  • [39星][4y] [Py] dungtv543/dutas Analysis PE file or Shellcode
  • [38星][5y] [C++] adamkramer/jmp2it Transfer EIP control to shellcode during malware analysis investigation
  • [11星][5y] [Py] debasishm89/qhook qHooK is very simple python script (dependent on pydbg) which hooks user defined Win32 APIs in any process and monitor then while process is running and at last prepare a CSV report with various interesting information which can help reverse engineer to track down / analyse unknown exploit samples / shellcode.

<a id="ae3243cf65f334dd979b7709d6d745d3"></a>文章

<a id="2783a12f735d75d4d9dd34aade4e27fd"></a>BypassXxx


<a id="68671811bf65fa44f770f9b7bf35edba"></a>AV

<a id="501a34037beb98f8db25e453dc8c6178"></a>工具

  • [322星][1m] [C#] hackplayers/salsa-tools ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched
  • [195星][1y] [Py] mr-un1k0d3r/unibyav a simple obfuscator that take raw shellcode and generate executable that are Anti-Virus friendly.
  • [177星][3y] [Py] arno0x/shellcodewrapper 支持多种语言的Shellcode包装器,支持编码/加密。可用于绕过杀软
  • [84星][2y] [C] hvqzao/foolavc foolav successor - loads DLL, executable or shellcode into memory and runs it effectively bypassing AV
  • [78星][1m] [Py] k8gege/scrun BypassAV ShellCode Loader (Cobaltstrike/Metasploit)

<a id="e4f187de8742002a534b4140989904a4"></a>文章


<a id="8c1f3c12de652e3cb2e2d92d28d762d8"></a>工具


<a id="fa01326b5bfe12e5417c0f4d30146245"></a>文章

<a id="82f62a71fbfb0aec18860663d4de5ec2"></a>ARM


<a id="9ebdbbcde063e2fd71a1f9fef001315a"></a>工具


<a id="c7014efbebcc4831883c878a9c4b1736"></a>文章

<a id="bfaa9390189b5c4ab46ca5631adf3453"></a>其他


<a id="16001cb2fae35b722deaa3b9a8e5f4d5"></a>工具

<a id="714ed53324dd30fc14a3ca7c02b9fc1c"></a>收集

<a id="98d70f3829393b5da364689bc902bab0"></a>新添加

<a id="d342759bd2543421de29133d9b376df8"></a>其他

  • [2425星][2y] [Py] secretsquirrel/the-backdoor-factory 为PE, ELF, Mach-O二进制文件添加Shellcode后门
  • [2209星][1m] [Py] trustedsec/unicorn 通过PowerShell降级攻击, 直接将Shellcode注入到内存
  • [664星][1y] [Rust] endgameinc/xori 自动化反汇编、静态分析库,适用于PE32, 32+ 和shellcode
  • [470星][3y] [Py] trustedsec/meterssh 将Shellcode注入内存,然后通过SSH隧道传输(端口任选,并伪装成普通SSH连接)
  • [430星][2m] [C] hasherezade/hollows_hunter Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
  • [225星][1m] [PS] outflanknl/excel4-dcom PowerShell和Cobalt Strike脚本,通过DCOM执行Excel4.0/XLM宏实现横向渗透(直接向Excel.exe注入Shellcode)

<a id="7d2b1d324dbfb20c3c6da343e9443a5c"></a>文章

<a id="596105c2fa0590982160279ebd1b1eac"></a>新添加

贡献

内容为系统自动导出, 有任何问题请提issue

Contributors

Showing top 1 contributor by commit count.

View all contributors on GitHub →

This article is auto-generated from alphaSeclab/shellcode-resources via the GitHub API.Last fetched: 6/22/2026