# Ch0pin/AVIator

Antivirus evasion project

Repository: https://github.com/Ch0pin/AVIator
Canonical: https://ross.abutalabs.com/products/aviator
Language: C#
License: GPL-3.0
License Family: copyleft
Topics: antivirus, bypass, backdoor, windows, trojan, shellcode, injection, backdoors, virus-total, av-evasion, av-b, backdooring, crypter, antivirus-testing, virus
Archived: true
Last push: 2025-01-19T12:53:05+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 2, release rhythm 35, longevity 100
- inputs: {"age_days": 3063, "days_push": 591, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, archived
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1161, forks 230 (observed 2026-08-28T04:03:49.298110+00:00)

## What it is
AV|Ator is a GUI backdoor generator that encrypts shellcode with AES and produces Windows executables that decrypt and inject the payload using techniques like process and thread injection to bypass antivirus detection. It is a C#/.NET tool aimed at red-teamers and security researchers testing AV evasion.

## Use cases
- generate encrypted shellcode executables that bypass antivirus
- test whether an AV product detects injected payloads
- encrypt meterpreter shellcode with AES and an IV
- spoof executable filenames with RTLO to look like pdf or txt files
- apply custom icons to generated payloads
- evaluate process injection techniques against EDR and AV on Windows

## When to choose
- you are a red-teamer or pentester needing an AV evasion payload generator
- you want to test antivirus detection of process injection on Windows
- you need a quick GUI tool to wrap shellcode in an encrypted executable

## When to avoid
- you need a stealthy production-grade C2 framework rather than a demo generator
- you require Linux or macOS payload targets
- you want a maintained tool with active development and support
- you lack authorization to test against protected systems

## Facets
- artifact type: application
- maturity: maintenance
- function: security, cryptography, penetration-testing
- domain: security, penetration-testing, windows
- platform: windows, cross-platform
- tags: av-evasion, shellcode, backdoor-generator, process-injection, crypter, red-team, offensive-security, payload-encryption, desktop

## Member repositories
- Ch0pin/AVIator (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:49.298110+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:31:40.349755+00:00, confidence not recorded.
  - readme: https://github.com/Ch0pin/AVIator (fetched 2026-08-28T04:03:49.298110+00:00, sha 76394d289f0c)
- Data as of 2026-08-30T08:39:29.467469+00:00.
