{"adoption": {"forks": 203, "observed_at": "2026-08-28T04:03:55.362829+00:00", "stars": 1188}, "canonical_url": "https://ross.abutalabs.com/products/darkloadlibrary", "card": {"archived": false, "artifact_type": "library", "description": "LoadLibrary for offensive operations", "domain": ["security", "penetration-testing", "windows"], "enriched": true, "function": ["security", "reverse-engineering"], "health_score": 20, "homepage": "https://www.mdsec.co.uk/2021/06/bypassing-image-load-kernel-callbacks/", "language": "C", "license": null, "license_family": "other", "maturity": "maintenance", "member_repos": ["bats3c/DarkLoadLibrary"], "name": "bats3c/DarkLoadLibrary", "platform": ["windows", "cpp"], "pushed_at": "2021-10-22T07:27:58+00:00", "repo": "bats3c/DarkLoadLibrary", "stars": 1188, "tags": ["dll-loading", "red-team", "offensive-security", "kernel-callback-bypass", "peb-unlinking", "malware-development"], "topics": [], "urls": [], "use_cases": ["load a DLL from memory without triggering image load kernel callbacks", "load a DLL without linking it to the PEB module list", "evade EDR detection of module loading during red team operations", "implement stealthy reflective DLL loading in C", "load a local DLL bypassing the standard Windows loader telemetry"], "what_it_is": "DarkLoadLibrary is a C library implementing an alternative to the Windows LoadLibrary API designed for offensive security operations. It loads DLLs from disk or memory while avoiding image load kernel callbacks and optionally bypassing PEB module linking to evade detection.", "when_to_avoid": ["you need a general-purpose, fully compatible DLL loader for legitimate applications", "you need a maintained, licensed library for production software", "you are not comfortable with low-level Windows internals in C"], "when_to_choose": ["you are writing offensive tooling or red team implants on Windows that need stealthy DLL loading", "you need to bypass image load kernel callback telemetry", "you want memory-based DLL loading with control over PEB registration"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/darkloadlibrary", "repo": "bats3c/DarkLoadLibrary", "role": "main", "score": 32}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:03:55.362829+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T06:23:23.590552+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aea30352baba9f0594c0632f2a85b85f0fb53ad3e5bc92f0b25179bc490cc41f", "fetched_at": "2026-08-28T04:03:55.362829+00:00", "kind": "readme", "missing": false, "url": "https://github.com/bats3c/DarkLoadLibrary"}, {"content_hash": "2d55961437009148476c806fae5638715d6f3fff67ceeff572a2ec8cdb0d95ea", "fetched_at": "2026-08-29T12:30:31.362085+00:00", "kind": "homepage", "missing": false, "url": "https://www.mdsec.co.uk/2021/06/bypassing-image-load-kernel-callbacks/"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:03:55.362829+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T06:23:23.590552+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aea30352baba9f0594c0632f2a85b85f0fb53ad3e5bc92f0b25179bc490cc41f", "fetched_at": "2026-08-28T04:03:55.362829+00:00", "kind": "readme", "missing": false, "url": "https://github.com/bats3c/DarkLoadLibrary"}, {"content_hash": "2d55961437009148476c806fae5638715d6f3fff67ceeff572a2ec8cdb0d95ea", "fetched_at": "2026-08-29T12:30:31.362085+00:00", "kind": "homepage", "missing": false, "url": "https://www.mdsec.co.uk/2021/06/bypassing-image-load-kernel-callbacks/"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T06:23:23.590552+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aea30352baba9f0594c0632f2a85b85f0fb53ad3e5bc92f0b25179bc490cc41f", "fetched_at": "2026-08-28T04:03:55.362829+00:00", "kind": "readme", "missing": false, "url": "https://github.com/bats3c/DarkLoadLibrary"}, {"content_hash": "2d55961437009148476c806fae5638715d6f3fff67ceeff572a2ec8cdb0d95ea", "fetched_at": "2026-08-29T12:30:31.362085+00:00", "kind": "homepage", "missing": false, "url": "https://www.mdsec.co.uk/2021/06/bypassing-image-load-kernel-callbacks/"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:03:55.362829+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:03:55.362829+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:03:55.362829+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T06:23:23.590552+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aea30352baba9f0594c0632f2a85b85f0fb53ad3e5bc92f0b25179bc490cc41f", "fetched_at": "2026-08-28T04:03:55.362829+00:00", "kind": "readme", "missing": false, "url": "https://github.com/bats3c/DarkLoadLibrary"}, {"content_hash": "2d55961437009148476c806fae5638715d6f3fff67ceeff572a2ec8cdb0d95ea", "fetched_at": "2026-08-29T12:30:31.362085+00:00", "kind": "homepage", "missing": false, "url": "https://www.mdsec.co.uk/2021/06/bypassing-image-load-kernel-callbacks/"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:03:55.362829+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:03:55.362829+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T06:23:23.590552+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aea30352baba9f0594c0632f2a85b85f0fb53ad3e5bc92f0b25179bc490cc41f", "fetched_at": "2026-08-28T04:03:55.362829+00:00", "kind": "readme", "missing": false, "url": "https://github.com/bats3c/DarkLoadLibrary"}, {"content_hash": "2d55961437009148476c806fae5638715d6f3fff67ceeff572a2ec8cdb0d95ea", "fetched_at": "2026-08-29T12:30:31.362085+00:00", "kind": "homepage", "missing": false, "url": "https://www.mdsec.co.uk/2021/06/bypassing-image-load-kernel-callbacks/"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:03:55.362829+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:03:55.362829+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:03:55.362829+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T06:23:23.590552+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aea30352baba9f0594c0632f2a85b85f0fb53ad3e5bc92f0b25179bc490cc41f", "fetched_at": "2026-08-28T04:03:55.362829+00:00", "kind": "readme", "missing": false, "url": "https://github.com/bats3c/DarkLoadLibrary"}, {"content_hash": "2d55961437009148476c806fae5638715d6f3fff67ceeff572a2ec8cdb0d95ea", "fetched_at": "2026-08-29T12:30:31.362085+00:00", "kind": "homepage", "missing": false, "url": "https://www.mdsec.co.uk/2021/06/bypassing-image-load-kernel-callbacks/"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:03:55.362829+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:03:55.362829+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T06:23:23.590552+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aea30352baba9f0594c0632f2a85b85f0fb53ad3e5bc92f0b25179bc490cc41f", "fetched_at": "2026-08-28T04:03:55.362829+00:00", "kind": "readme", "missing": false, "url": "https://github.com/bats3c/DarkLoadLibrary"}, {"content_hash": "2d55961437009148476c806fae5638715d6f3fff67ceeff572a2ec8cdb0d95ea", "fetched_at": "2026-08-29T12:30:31.362085+00:00", "kind": "homepage", "missing": false, "url": "https://www.mdsec.co.uk/2021/06/bypassing-image-load-kernel-callbacks/"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T06:23:23.590552+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aea30352baba9f0594c0632f2a85b85f0fb53ad3e5bc92f0b25179bc490cc41f", "fetched_at": "2026-08-28T04:03:55.362829+00:00", "kind": "readme", "missing": false, "url": "https://github.com/bats3c/DarkLoadLibrary"}, {"content_hash": "2d55961437009148476c806fae5638715d6f3fff67ceeff572a2ec8cdb0d95ea", "fetched_at": "2026-08-29T12:30:31.362085+00:00", "kind": "homepage", "missing": false, "url": "https://www.mdsec.co.uk/2021/06/bypassing-image-load-kernel-callbacks/"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T06:23:23.590552+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aea30352baba9f0594c0632f2a85b85f0fb53ad3e5bc92f0b25179bc490cc41f", "fetched_at": "2026-08-28T04:03:55.362829+00:00", "kind": "readme", "missing": false, "url": "https://github.com/bats3c/DarkLoadLibrary"}, {"content_hash": "2d55961437009148476c806fae5638715d6f3fff67ceeff572a2ec8cdb0d95ea", "fetched_at": "2026-08-29T12:30:31.362085+00:00", "kind": "homepage", "missing": false, "url": "https://www.mdsec.co.uk/2021/06/bypassing-image-load-kernel-callbacks/"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T06:23:23.590552+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "aea30352baba9f0594c0632f2a85b85f0fb53ad3e5bc92f0b25179bc490cc41f", "fetched_at": "2026-08-28T04:03:55.362829+00:00", "kind": "readme", "missing": false, "url": "https://github.com/bats3c/DarkLoadLibrary"}, {"content_hash": "2d55961437009148476c806fae5638715d6f3fff67ceeff572a2ec8cdb0d95ea", "fetched_at": "2026-08-29T12:30:31.362085+00:00", "kind": "homepage", "missing": false, "url": "https://www.mdsec.co.uk/2021/06/bypassing-image-load-kernel-callbacks/"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["no_releases", "no_license"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1903, "days_push": 1776, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 32, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}