1y0n/AV_Evasion_Tool
掩日 - 免杀执行器生成工具 observed · 2026-08-28
Health v2 · maintenance only
39/100
- Activity 37
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2323
- days_rel: n/a
- days_push: 380
- n_releases_24m: 0
Adoption not part of the score
2763 stars · 399 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
YanRi (AV_Evasion_Tool) is a Windows GUI tool for red teams that generates loaders to evade antivirus detection of shellcode payloads, supporting C (tdm-gcc/tcc) and Go compilation. The open-source version is no longer updated; development has moved to an online version.
Use cases
- generate an antivirus-evading loader for shellcode
- bypass Windows Defender for a Cobalt Strike payload
- compile shellcode into a small executable with tcc
- create a red team payload loader on Windows
- split payload locally or over network to evade detection
- compare antivirus detection results for generated payloads
When to choose
- you are an authorized red teamer needing a quick Windows payload loader generator
- you want a GUI tool that supports both C and Go loaders
- you need tiny loader binaries that can be UPX-compressed
When to avoid
- the open-source version is no longer updated, so evasion techniques may be outdated
- you need Linux or macOS support - it is Windows-only
- you want a fully tested, production-grade tool - the author notes limited testing
- you lack authorization for offensive security testing
Facets
application · maturity maintenance
security cryptography developer-tools security penetration-testing windows windows cli red-team av-evasion payload-loader shellcode cobalt-strike offensive-security anti-detection desktop
1 source
- readme: https://github.com/1y0n/AV_Evasion_Tool · fetched 2026-08-28 · 056bd5cb895b
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| 1y0n/AV_Evasion_Tool | main | 39 |
For agents
markdown · JSON · MCP: product_card(name="1y0n/AV_Evasion_Tool")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem