{"adoption": {"forks": 195, "observed_at": "2026-08-28T04:03:19.521486+00:00", "stars": 1037}, "canonical_url": "https://ross.abutalabs.com/products/filelesspeloader", "card": {"archived": false, "artifact_type": "cli-tool", "description": "Loading Remote AES Encrypted PE in memory , Decrypted it and run it ", "domain": ["security", "penetration-testing"], "enriched": true, "function": ["security", "cryptography", "developer-tools"], "health_score": 20, "homepage": null, "language": "C++", "license": "MIT", "license_family": "permissive", "maturity": "maintenance", "member_repos": ["SaadAhla/FilelessPELoader"], "name": "SaadAhla/FilelessPELoader", "platform": ["windows", "cpp", "cli"], "pushed_at": "2023-08-29T21:46:11+00:00", "repo": "SaadAhla/FilelessPELoader", "stars": 1037, "tags": ["red-team", "fileless-execution", "pe-loader", "aes-encryption", "offensive-security", "malware-development", "pentesting"], "topics": ["blueteam", "hacking", "hacking-tool", "hacking-tools", "malware", "malware-analysis", "malware-development", "malware-research", "offensive-security", "pentesting", "pentesting-tool", "pentesting-tools", "redteam"], "urls": [], "use_cases": ["load a remote encrypted payload entirely in memory", "run PE executables without touching disk during pentests", "test EDR detection of fileless execution techniques", "deliver AES-encrypted red team tooling", "study in-memory PE loading and decryption techniques", "simulate malware-like execution for blue team training"], "what_it_is": "A C++ tool that fetches an AES-encrypted Windows PE executable from a remote location, decrypts it in memory, and executes it without writing to disk (fileless loading). It is aimed at red team and penetration testing scenarios.", "when_to_avoid": ["you need a full-featured C2 framework with post-exploitation capabilities", "you require cross-platform support beyond Windows", "you want a maintained tool with active development and recent updates", "you need stealth features like AMSI or ETW bypass"], "when_to_choose": ["you need fileless in-memory execution of Windows PE payloads", "you want payloads encrypted at rest with AES and fetched remotely", "you are doing authorized red team or penetration testing work", "you want a simple open-source reference for PE memory loading"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/filelesspeloader", "repo": "SaadAhla/FilelessPELoader", "role": "main", "score": 31}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:03:19.521486+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T07:04:21.307705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fb06c804c4c6a002c28a8c6fa5ff7a4386eba7a53660a6ab2816e36ed3347311", "fetched_at": "2026-08-28T04:03:19.521486+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SaadAhla/FilelessPELoader"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:03:19.521486+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T07:04:21.307705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fb06c804c4c6a002c28a8c6fa5ff7a4386eba7a53660a6ab2816e36ed3347311", "fetched_at": "2026-08-28T04:03:19.521486+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SaadAhla/FilelessPELoader"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T07:04:21.307705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fb06c804c4c6a002c28a8c6fa5ff7a4386eba7a53660a6ab2816e36ed3347311", "fetched_at": "2026-08-28T04:03:19.521486+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SaadAhla/FilelessPELoader"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:03:19.521486+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:03:19.521486+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:03:19.521486+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T07:04:21.307705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fb06c804c4c6a002c28a8c6fa5ff7a4386eba7a53660a6ab2816e36ed3347311", "fetched_at": "2026-08-28T04:03:19.521486+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SaadAhla/FilelessPELoader"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:03:19.521486+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:03:19.521486+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T07:04:21.307705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fb06c804c4c6a002c28a8c6fa5ff7a4386eba7a53660a6ab2816e36ed3347311", "fetched_at": "2026-08-28T04:03:19.521486+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SaadAhla/FilelessPELoader"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:03:19.521486+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:03:19.521486+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:03:19.521486+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T07:04:21.307705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fb06c804c4c6a002c28a8c6fa5ff7a4386eba7a53660a6ab2816e36ed3347311", "fetched_at": "2026-08-28T04:03:19.521486+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SaadAhla/FilelessPELoader"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:03:19.521486+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:03:19.521486+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T07:04:21.307705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fb06c804c4c6a002c28a8c6fa5ff7a4386eba7a53660a6ab2816e36ed3347311", "fetched_at": "2026-08-28T04:03:19.521486+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SaadAhla/FilelessPELoader"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T07:04:21.307705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fb06c804c4c6a002c28a8c6fa5ff7a4386eba7a53660a6ab2816e36ed3347311", "fetched_at": "2026-08-28T04:03:19.521486+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SaadAhla/FilelessPELoader"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T07:04:21.307705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fb06c804c4c6a002c28a8c6fa5ff7a4386eba7a53660a6ab2816e36ed3347311", "fetched_at": "2026-08-28T04:03:19.521486+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SaadAhla/FilelessPELoader"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T07:04:21.307705+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "fb06c804c4c6a002c28a8c6fa5ff7a4386eba7a53660a6ab2816e36ed3347311", "fetched_at": "2026-08-28T04:03:19.521486+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SaadAhla/FilelessPELoader"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 93, "rhythm": 35}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1302, "days_push": 1100, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 31, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}